Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c504cbf43f12528…

MALICIOUS

PDF

79.2 KB Created: 2021-03-17 18:41:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 03701990cda6e294132e37082a9490f9 SHA-1: 769c542a8730de813ade310f4b8d97f44c5dc1ba SHA-256: 3c504cbf43f12528b6f78fed66b57e7a44e781a59c4492c2b8b3fc60a35958d1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that leads to a website offering cracked software, indicating a phishing or malware distribution attempt. The ClamAV detection and ML classifier strongly suggest malicious intent. The presence of multiple suspicious URLs further supports the conclusion that this file is part of a campaign to trick users into downloading potentially harmful software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/wix?keyword=go+sms+pro+premium+apk+cracked
    • http://all-casino.xyz/jonopuzowefidixutuzafasoa6vy6.pdf
    • http://torchland.xyz/volkswagen_trans_fluid_typejucib.pdf
    • https://biwawidojimu.weebly.com/uploads/1/3/4/6/134648839/4661e509545b7c1.pdf
    • https://bowasizavaxilek.weebly.com/uploads/1/3/4/0/134042597/656a40c2418050.pdf
    • https://simebofes.weebly.com/uploads/1/3/1/4/131438459/fikarenuvapuvu.pdf
    • http://youralteragoods.com/nolamajrv0m8.pdf
    • http://dsv-trening.ru/third_age_divide_and_conquer_install4c3m6.pdf
    • http://allieshouseofhope.com/811309988461qk4t.pdf
    • http://amin-ukraine.net/51758976366gt030.pdf
    • http://alphabitx.com/hp_elitedesk_800_g1_sff_spec_sheetbpfqf.pdf
    • http://fusitekive.iblogger.org/broadsoft_communicator_windows.pdf
    • http://beruvutekimeged.22web.org/audio_from_website_python.pdf
    • http://lnstagram-helping.live/editor_de_presentaciones_electronicas_definicionbu3rf.pdf
    • http://mazezoda.22web.org/how_to_overcome_emotional_abuse_from_father.pdf
    • http://nefuzixitelu.iblogger.org/android_19_and_20_dbz.pdf
    • http://straponartist.com/wefulegawokoganav75jqp.pdf
    • http://luranowebereni.22web.org/alien_shooter_mod_apk_happymod.pdf
    • http://tersq.fun/trane_ac_parts_near_me45pmw.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://lofukikusi.epizy.com/descriptive_writing_planning_sheets.pdf
    • http://pugipig.rf.gd/capacity_building_definition.pdf
    • http://fepoxojosatomu.epizy.com/guvojotokujedafa.pdf
    • http://daxeletibumu.rf.gd/burma_tv_apk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e962.bin
ba206140b33a342cc6b5183972f36384349da94ed2c401aef4ab6113023231d9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE962 4976 bytes
font_01_sfnt_off0000fa48.bin
4ff136933c416c2f436fe69e6b2f1e43438ab14fb4dc72f2293446745e7e6262
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA48 10824 bytes
font_02_sfnt_off00011f6f.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F6F 4324 bytes