Malicious PDF — malware analysis report

Static analysis result for SHA-256 2facee7c4d4c26e2…

MALICIOUS

PDF

73.1 KB Created: 2020-11-14 19:59:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: 1d63fa5cc96cb034f149e0ba80d53b72 SHA-1: 5c3c6d923ab4f56be853062bf53227f5944425e0 SHA-256: 2facee7c4d4c26e28958af017e2dd855d2971d63721e9e3eca1693775d515219
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/strik?utm_term=john+deere+450+dozer+service+manual+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4403680/normal_5f9c5c78685bd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375358/normal_5f99c52836c44.pdfIn PDF document text
    • https://mupoveno.weebly.com/uploads/1/3/4/3/134371030/941128.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384154/normal_5fa185d47cbec.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4376120/normal_5f8d8480d78ab.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404313/normal_5f92b30d60a0d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391620/normal_5faf9ce4667ca.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403563/normal_5fa3095e8d7b0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/pisedij/vixiforexisavozezowu.pdfIn PDF document text
    • https://s3.amazonaws.com/suzixegazunow/honeywell_wifi_thermostat_rth6580wf_review.pdfIn PDF document text
    • https://s3.amazonaws.com/viboxikuz/shelby_county_sheriff_warrant_search.pdfIn PDF document text
    • https://s3.amazonaws.com/gupuso/xibirozavode.pdfIn PDF document text
    • https://s3.amazonaws.com/vexeliku/dan_bilzerian_song_djpunjab.pdfIn PDF document text
    • https://s3.amazonaws.com/mamukawaxatali/abortion_law_in_the_philippines.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d168.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD168 3852 bytes
SHA-256: 5c932699bfdfde77f21141451dd86e307bdde6332a14910906ddcdcd5fbeedad
font_01_sfnt_off0000df01.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDF01 5848 bytes
SHA-256: 88891c6c5b369ae8868053d844a5840bdb66772da83d5e414164f5f08f44a25f
font_02_sfnt_off0000f2da.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF2DA 10620 bytes
SHA-256: 8581564838408903876c459e5a203fe9e5bf15ca141fb7824ac31f47d7e63ada