Malicious PDF — malware analysis report

Static analysis result for SHA-256 33986dd1f7990ad6…

MALICIOUS

PDF

89.0 KB Created: 2021-04-07 15:26:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: c8658db9558fd6f6e443f884f2aab439 SHA-1: e2f3b54bb944da1f92f3e178266ae399f5a85a2d SHA-256: 33986dd1f7990ad6fc51693afc1fe7d003c4aa97d3fc63f78fab86b5a624d97f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as a malicious PDF by ML classifiers and ClamAV, indicating a phishing or trojan payload. The embedded URLs, though many are benign, suggest an attempt to redirect the user to potentially malicious content. The document body, while heavily obfuscated, contains references to 'traditional values' and 'wkhtmltopdf', hinting at a social engineering lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.dgs-interparts.be/sites/default/files/60165950635.pdf In PDF document text
    • http://cicatsalud.com/html/sites/default/files/webform/99368311749.pdfIn PDF document text
    • http://www.muttypawsacademy.com/sites/default/files/webform/vaccines/65827293628.pdfIn PDF document text
    • https://www.dgs-interparts.be/sites/default/files/muvok.pdfIn PDF document text
    • http://cicatsalud.com/html/sites/default/files/webform/buvonajevomowetizebijix.pdfIn PDF document text
    • http://www.muttypawsacademy.com/sites/default/files/webform/vaccines/2944445507.pdfIn PDF document text
    • http://www.muttypawsacademy.com/sites/default/files/webform/vaccines/37570077738.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/kubuxodadiwozubak.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://feedproxy.google.com/~r/Uplcv/~3/LPIa9PGmDLg/uplcv?utm_term=what+are+traditional+values+pdfPDF link annotation
    • https://lib.asu.edu/system/files/webform/nexeginexepor.pdfIn PDF document text
    • https://campusrec.princeton.edu/system/files/webform/18758627140.pdfIn PDF document text
    • https://www.healthdata.org/sites/default/files/resumes/58023923203.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011e3f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11E3F 5200 bytes
SHA-256: 02363088a9605f9b4e6f21eff1902710c6833bda898d6525f948a4fdb2ddc95a
font_01_sfnt_off00012ffc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12FFC 11140 bytes
SHA-256: 67754a7a6b8c6baa8c03dcdc73e2937800bdef8c93e949499b8634d262c3693a