Malicious PDF — malware analysis report

Static analysis result for SHA-256 33f043a76f02b494…

MALICIOUS

PDF

78.1 KB Created: 2021-03-10 05:23:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 48c54570e9fc0403727d77e5dcfe69c3 SHA-1: bc121b82a6518a5eff653911dd76ae438b3a41cf SHA-256: 33f043a76f02b494be8c21284e3d34fd1970094a1cf4808e457f80cb4838cb01
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that contains numerous embedded URLs, many of which point to potentially malicious domains. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The document body, though heavily obfuscated, suggests a lure related to academic papers, aligning with common phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=makalah+akuntansi+syariah+pdf
    • https://static.s123-cdn-static.com/uploads/4418370/normal_6003ceaf3756e.pdf
    • https://bawosizegidaw.weebly.com/uploads/1/3/1/4/131411147/bfb231030f1f9e3.pdf
    • https://fuxiwajusefu.weebly.com/uploads/1/3/4/6/134617271/9117094.pdf
    • http://italiabeach.space/978182552335lyuq.pdf
    • https://gebapawuvafiv.weebly.com/uploads/1/3/4/5/134519736/7259333.pdf
    • https://static.s123-cdn-static.com/uploads/4420752/normal_60011f3ea25d7.pdf
    • http://ebay-coupon.ru/wolodunipuxesuvinlq7bn.pdf
    • http://fartook.online/android_arduino_wifi_control_devices_with_esp8266_moduleagndy.pdf
    • http://item-mask.top/international_cost_of_living_index_by_city9vm60.pdf
    • http://liketime.online/mekivilubewedatexugeciorw.pdf
    • https://gekowodi.weebly.com/uploads/1/3/5/3/135321574/vitidanizarod.pdf
    • https://zunexoxefa.weebly.com/uploads/1/3/5/3/135340588/7003062.pdf
    • https://cdn-cms.f-static.net/uploads/4465400/normal_5fd829de55b7a.pdf
    • https://cdn-cms.f-static.net/uploads/4502906/normal_601787ce48c83.pdf
    • https://zimavilagapiwe.weebly.com/uploads/1/3/2/7/132712623/waregoseg.pdf
    • http://pubgucbayim.com/scoop_it_up_minute_to_win_itmmqg8.pdf
    • https://sesadawaroni.weebly.com/uploads/1/3/5/2/135295108/panizewugulug_runogerubamima.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://c36efdde-2309-4ce2-a10d-b6df2ce12cd8.filesusr.com/ugd/e98059_9c03483fc204409fab5a5a95717c4e1e.pdf?index=true
    • https://fa202315-5cd5-4006-9a99-7c5d4406650e.filesusr.com/ugd/61804c_8b104629241549498e7a71f6ff0d6400.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e940.bin
156bc211a5cfbe3450db55ddc42e55ce78221d6873de9145ec526247f76ed916
pdf-font-stream PDF embedded font (sfnt) at offset 0xE940 4952 bytes
font_01_sfnt_off0000fa05.bin
d935b5318e396c1efe9b6fe0c43d0e4e869fa8da0e1ac84e53ac44198a9e5668
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA05 10232 bytes
font_02_sfnt_off00011d1c.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D1C 4324 bytes