Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c2c397bd37ab27c…

MALICIOUS

PDF

81.3 KB Created: 2021-05-02 19:59:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: be033b7ba72cc198980488bf57de7dac SHA-1: e8d78d1c5ee525c1c9d87c08798743d15c76d82a SHA-256: 3c2c397bd37ab27c311dbcf29ab5b4c22e0cc40dadd79fd5f95607552a94dbb9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded URLs that redirect to malicious domains, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. Although no scripts were explicitly extracted, the presence of external URIs and the overall detection profile point towards a phishing lure designed to redirect users to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/strik?utm_term=american+gods+season+2+episode+8+review
    • https://static.s123-cdn-static.com/uploads/4489255/normal_600210a083cbf.pdf
    • http://slmit.fun/70384432600og59y.pdf
    • https://cdn.sqhk.co/bupewazadufa/ejrghgh/jevasapagi.pdf
    • http://trychambre.xyz/what_stocks_to_buy_for_a_beginnersazyle.pdf
    • https://static.s123-cdn-static.com/uploads/4417523/normal_5fe47700cc97b.pdf
    • https://static.s123-cdn-static.com/uploads/4375515/normal_5fd0536663a7c.pdf
    • http://wiregabjuk.fun/jogugodudomekopixh3.pdf
    • https://cdn.sqhk.co/vobevufubito/XPhbXVX/33902259383.pdf
    • https://cdn-cms.f-static.net/uploads/4425211/normal_6023d889f2af0.pdf
    • http://lg-copyright.com/biological_evolution_of_man375g7.pdf
    • http://sushibara.net/2841494270193scm.pdf
    • https://cdn.sqhk.co/zozimevoket/wRjfieM/fitbit_versa_3_vs_versa_2.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c02af757-eecd-4806-8b65-100e2cdb94ee/wokotugupawagekeja.pdf
    • https://uploads.strikinglycdn.com/files/a0aad76e-e14a-4c9d-8db9-713680879341/6-1_skills_practice_angles_of_polygons_page_8_answers.pdf
    • https://uploads.strikinglycdn.com/files/24bee1be-ad61-4b93-a7bb-41cf6a53d9ab/zuvenavabaxajopobadeduk.pdf
    • https://uploads.strikinglycdn.com/files/7a3b94c4-4291-48bc-8b72-c93b58c5cdb3/the_worry_trick_summary.pdf
    • https://uploads.strikinglycdn.com/files/3b07ac5b-169d-409b-8a36-d72c990a6b76/what_are_the_3_major_rivers_in_the_us.pdf
    • https://uploads.strikinglycdn.com/files/b7abbae5-3da6-443a-b021-5b16986674d6/kiwikunelale.pdf
    • https://uploads.strikinglycdn.com/files/484dd9ec-76e5-4204-8ffd-a829cd41a8bc/38650788656.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010060.bin
0dd5ae965f3e7fd6719ed0067657d9de0f0f1b659799d41d9c572a747a4fbcf8
pdf-font-stream PDF embedded font (sfnt) at offset 0x10060 5828 bytes
font_01_sfnt_off00011430.bin
9086398742990bea9a3d93c97048644eb49259488fcc372d46808a4e2e8ace2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x11430 10468 bytes