Malicious PDF — malware analysis report

Static analysis result for SHA-256 317e892bc099ff50…

MALICIOUS

PDF

86.1 KB Created: 2021-04-01 06:57:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 39f088b3b4b870ad03214a59ba214700 SHA-1: 2a9b2c5e966e4e4b0cc714d602ac1469702f5618 SHA-256: 317e892bc099ff5049ee3e6b1d621680386f8d0a8044bb02594d56beb6291a23
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by ML classifiers and ClamAV as malicious, specifically identified as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into visiting a phishing site. No scripts were extracted, but the presence of external URIs and the overall classification strongly suggest a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=conformational+isomers+pdf
    • https://cdn-cms.f-static.net/uploads/4472186/normal_604979016205d.pdf
    • https://liwavijej.weebly.com/uploads/1/3/4/3/134379327/vijojizuvabenofot.pdf
    • https://rorujazikuje.weebly.com/uploads/1/3/1/3/131379225/b8c1e76ac.pdf
    • https://cdn-cms.f-static.net/uploads/4368500/normal_600e05f92c218.pdf
    • http://kixurox.getenjoyment.net/76957434108.pdf
    • https://kiwiwutirove.weebly.com/uploads/1/3/4/7/134707888/nivefi_mesetujufekoziw_rilinejidokaga_kutosaguzeba.pdf
    • https://famonusowofem.weebly.com/uploads/1/3/4/3/134349488/5964753.pdf
    • https://gogabaxada.weebly.com/uploads/1/3/4/8/134852864/wuloranitumenofigi.pdf
    • http://pefiworawodud.mypressonline.com/haitian_creole_language.pdf
    • https://static.s123-cdn-static.com/uploads/4369909/normal_5ff08e5f4e918.pdf
    • http://potawuzaj.medianewsonline.com/what_is_included_in_personal_auto_policy.pdf
    • https://cdn-cms.f-static.net/uploads/4407086/normal_601280878d2c6.pdf
    • https://cdn-cms.f-static.net/uploads/4387929/normal_605fbdd17a0c1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2dcf1b72-07de-4905-8411-afb2794de042/84130542428.pdf
    • https://s3.amazonaws.com/wulotugadag/33273154092.pdf
    • https://uploads.strikinglycdn.com/files/96f932bb-54d7-4c98-9d44-9a55525ce583/yoga_dog_bookends.pdf
    • https://s3.amazonaws.com/toguvaju/goblin_dawn_of_the_dead_soundtrack.pdf
    • https://uploads.strikinglycdn.com/files/a4ffabc2-86e3-4846-a104-0d28ada89283/90597890140.pdf
    • https://s3.amazonaws.com/vapelurowar/12094006738.pdf
    • http://logiweliziweje.onlinewebshop.net/95698770734.pdf
    • https://s3.amazonaws.com/matogapibelifiv/kowonutoxaketinep.pdf
    • https://uploads.strikinglycdn.com/files/f1ca6388-5e71-49c5-b2aa-fe444b24690a/857209169.pdf
    • https://uploads.strikinglycdn.com/files/25a1e645-6fe0-4f4f-82ba-450b0dc974e2/air_fryer_recipes_indian_youtube.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fcdf.bin
c24ac9c7614395a10946d0becd9fd7133839c2e25ae199a112bf55cb32d7b720
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCDF 5092 bytes
font_01_sfnt_off00010e12.bin
a4fdd04871c0a58ceac2093866c5d1eda515aff95a310deb90d734f53d0a2e42
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E12 11528 bytes
font_02_sfnt_off000135d5.bin
5bb2a7a6380d1dfafb539ecff73d32ebbe261088a673e400f34aca4fbad20734
pdf-font-stream PDF embedded font (sfnt) at offset 0x135D5 16152 bytes