Malicious PDF — malware analysis report

Static analysis result for SHA-256 3902cd7b11a8256e…

MALICIOUS

PDF

76.7 KB Created: 2021-03-27 16:11:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 61c91258fc0c4d0abb9fd0504df71be7 SHA-1: b50cde12707ce444211eef85a0a76db2ddc0fd16 SHA-256: 3902cd7b11a8256e506c994a2f72d3a31c209a1a5d0d2c0dffc1e0ed009ff85f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URL pointing to a potential second-stage payload. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. The presence of external URIs and the overall structure suggest an attempt to trick users into downloading further malicious content, masquerading as a legitimate software installer.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=java+for+pc+32+bit
    • http://wobafobigo.mywebcommunity.org/fegelowamotitexiwelosito.pdf
    • http://medicalpracticementor.com/problem_solving_activities_for_elementary_studentspm11b.pdf
    • http://nevogixire.22web.org/owen_dulce_et_decorum_est.pdf
    • http://ourfanz.com/songs_that_bring_back_memories41ju3.pdf
    • http://hellesypakk.online/alcatel_pixi_4024e_specs3z0c5.pdf
    • https://cdn-cms.f-static.net/uploads/4486763/normal_605100bc5885d.pdf
    • http://nidewopovuwubo.mypressonline.com/fowofexikukulilate.pdf
    • http://form-lnstagramverifiedbadges.com/the_silence_of_the_lambs_movie_google_drivesb9sl.pdf
    • https://static.s123-cdn-static.com/uploads/4489983/normal_5ff116089d6d1.pdf
    • https://cdn-cms.f-static.net/uploads/4428052/normal_6046682aca211.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/nutanigonu/41442016431.pdf
    • https://s3.amazonaws.com/gupojakami/4178795944.pdf
    • https://s3.amazonaws.com/nisiwanolom/60748305296.pdf
    • https://s3.amazonaws.com/dufekifaral/brs_pathology_2018_free_download.pdf
    • https://s3.amazonaws.com/retobifulipo/63917396599.pdf
    • https://s3.amazonaws.com/viregujipowuru/46848484069.pdf
    • http://fevupepetifus.rf.gd/12222623678.pdf
    • http://netuvorib.epizy.com/ashes_cricket_2013.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e458.bin
88e51e94c213e80e0eff483bae20dbab22f19db40339e0b5eb253b6d9e3b7c01
pdf-font-stream PDF embedded font (sfnt) at offset 0xE458 4848 bytes
font_01_sfnt_off0000f4e6.bin
4f72ed73fe3c16ef5a691f3353663064abe6b5e9937b0b12e35b7e5b524ef72d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4E6 10468 bytes
font_02_sfnt_off0001188b.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1188B 4324 bytes