Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c77f4171ece568b…

MALICIOUS

PDF

71.0 KB Created: 2021-02-17 05:10:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c914b3ce31e4620b17f557248f316534 SHA-1: 30334d6ee02d33d49ae7929a4b1fb7599c6d7521 SHA-256: 3c77f4171ece568b93dc8c9feada7f669fbb07a7503574488f3cef7152386e0f
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains heuristics indicating it is a phishing lure, likely attempting to trick users into clicking embedded links. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were directly extracted, the presence of numerous external URLs, including one that appears to be the primary lure, points towards a phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=how+to+fill+out+blueline+receipt+book
    • https://cdn.sqhk.co/gorokipo/Peagggd/vapuzif.pdf
    • https://cdn.sqhk.co/jilelemo/haThfkj/manozijukowelilemenixu.pdf
    • https://cdn.sqhk.co/xenudipu/iifhgix/jerebuzumon.pdf
    • https://cdn-cms.f-static.net/uploads/4388842/normal_601e67bd70747.pdf
    • http://busibear.com/slope_and_linear_equations_worksheetrgybz.pdf
    • https://wobomiti.weebly.com/uploads/1/3/4/5/134501920/8038131.pdf
    • https://pazopoxe.weebly.com/uploads/1/3/5/2/135293382/34198f880.pdf
    • https://static.s123-cdn-static.com/uploads/4481999/normal_5ffa80113aa76.pdf
    • http://bluetea.space/41063031485n3suo.pdf
    • http://triple-doska6.club/wumuxuihkr3.pdf
    • https://cdn.sqhk.co/vevigagexoxa/zOhf3gi/kozunizusivela.pdf
    • https://cdn-cms.f-static.net/uploads/4415309/normal_5fdab2c289e97.pdf
    • http://kostlike.site/botitosevagimozukomoper7yw1i.pdf
    • http://de-bewertung-id2842384.icu/dragon_ball_pipeso6sly.pdf
    • https://xefesikixote.weebly.com/uploads/1/3/1/4/131437823/c357203428d45f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zerujafulo.rf.gd/wow_assassin_rogue_pvp_guide.pdf
    • http://jutesokom.rf.gd/mefakulaxapajozurevikiz.pdf
    • http://moposafasamik.rf.gd/california_highway_patrol_citation_number.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000db6d.bin
6f1bdcc1830f6bdca78f33cdb59e831e067b1664f70ec7e5b574179ba0fe01a8
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB6D 4880 bytes
font_01_sfnt_off0000ec2b.bin
ae409fe9b119a2bf215fac10e23c1a83cc5257b211095913c9d38dc675dcc19f
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC2B 10144 bytes