Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a20494557a7afc7…

MALICIOUS

PDF

79.5 KB Created: 2021-04-03 20:45:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7585765cd9a976fa67aabf4c31158373 SHA-1: 61947ca8308cb64e4ebee000d4b3b2906d3072bc SHA-256: 3a20494557a7afc7b614e01838d1e5a0cf47e15c4a3551472d2f0200a475a885
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a malicious site or download further payloads. The document body, though heavily obfuscated, suggests a lure related to a crossword clue, aligning with phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=gabriel+crossword+clue
    • http://xorabawik.medianewsonline.com/50421715988.pdf
    • https://static.s123-cdn-static.com/uploads/4411691/normal_6000139f86ccc.pdf
    • http://sodalabs.club/thousand_splendid_suns_summary_chapter_40bep5b.pdf
    • http://registrat.space/70531311250ws53g.pdf
    • https://static.s123-cdn-static.com/uploads/4374013/normal_5fdd767fcdfb0.pdf
    • http://sayfelengs.space/xelonisunubidanezimesadx023.pdf
    • http://rotirir.mypressonline.com/ahead_of_the_curve_book.pdf
    • https://cdn-cms.f-static.net/uploads/4453906/normal_604dc25e5ac4a.pdf
    • https://cdn-cms.f-static.net/uploads/4387565/normal_6011dfa3864f2.pdf
    • http://aycotoro0.xyz/muxaraf5prx.pdf
    • http://wabaxifejem.sportsontheweb.net/88461642708.pdf
    • http://kugewezebuvigiw.mygamesonline.org/vuzijiki.pdf
    • https://cdn.sqhk.co/momebuman/R4v7qaC/download_street_fighter_4_champion_edition_mod.pdf
    • https://cdn-cms.f-static.net/uploads/4388062/normal_6047b8c335fc5.pdf
    • https://cdn.sqhk.co/seworani/jigegj2/police_car_smash_game.pdf
    • http://lakujalinifibo.mypressonline.com/kuwubobelivugumiwikik.pdf
    • https://cdn.sqhk.co/sibamoxa/hcaiaii/99150227659.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://rekobive.epizy.com/integrity_selling_for_the_21st_century.pdf
    • http://maxuluxusit.atwebpages.com/handbook_of_electronics_and_communication_engineering_download.pdf
    • http://mixonal.epizy.com/adobe_reader_portable_download.pdf
    • http://papumubi.epizy.com/short_a_sound_words_list.pdf
    • http://zejusamipokera.myartsonline.com/does_dimethyl_ether_have_ionic_intermolecular_forces.pdf
    • http://gogujigasad.onlinewebshop.net/54322996851.pdf
    • http://pekurixapomasil.epizy.com/zevawoketaf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fa34.bin
9e365ae27391f3602542506a1be0e0359098072f4f8dabafad140a633c3a7ae4
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA34 5196 bytes
font_01_sfnt_off00010bfc.bin
5b94adde431f3b15d11c29149fb9b1ee3f81b53f89b367beb270de26d0b5f103
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BFC 10788 bytes