Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f58f4380a1f02e2…

MALICIOUS

PDF

68.7 KB Created: 2021-03-22 20:38:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aa6d68dfaa9f9331cb08403da485af2f SHA-1: 7943b1636af3fb13a87251834ce238c6a5324e92 SHA-256: 3f58f4380a1f02e23e45c641eddd41de88a98ca739c9033d2528b161f45b3df1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. The embedded URL 'https://pelibifir.ru/aws?utm_term=the+bedford+handbook+with+2020+apa+update' strongly suggests a phishing attempt, likely to steal credentials or distribute further malware. While no scripts were explicitly extracted, the nature of the detection and the presence of numerous suspicious URLs indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/aws?utm_term=the+bedford+handbook+with+2020+apa+update
    • http://prostosite.site/pijilamisujupizazeneguzvr6j3.pdf
    • https://tujozidu.weebly.com/uploads/1/3/4/6/134694944/7033423.pdf
    • https://cdn.sqhk.co/mowamukar/idygdm0/84553949118.pdf
    • http://cashfree.store/2007_altima_service_manual2v0kt.pdf
    • https://static.s123-cdn-static.com/uploads/4422906/normal_5feb173cd9903.pdf
    • https://toxoladosa.weebly.com/uploads/1/3/4/4/134479392/jupolep-vewewil-vifaguz.pdf
    • https://guretaximijogu.weebly.com/uploads/1/3/0/7/130739376/9998758.pdf
    • https://xokebewogaxuwu.weebly.com/uploads/1/3/4/5/134588239/venezimima.pdf
    • https://cdn.sqhk.co/mokabawimav/hjfdMDy/23118413417.pdf
    • https://cdn.sqhk.co/mojikeke/aDijUQi/ringworm_infection_treatment.pdf
    • https://cdn-cms.f-static.net/uploads/4495244/normal_600f49a891300.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/1c4f3a64-023d-4464-9839-fb038f6903c5/where_to_watch_the_hobbit_trilogy_for_free.pdf
    • https://uploads.strikinglycdn.com/files/198d3864-9f3e-44bb-bfdc-fef58d977256/how_much_do_construction_companies_spend_on_safety.pdf
    • https://uploads.strikinglycdn.com/files/89a6fe3a-61b2-40bc-ae32-afb483a5138a/what_is_derivational_affixes_in_english.pdf
    • https://s3.amazonaws.com/bagisi/lanumovuxanosilezagofo.pdf
    • https://uploads.strikinglycdn.com/files/5b2ec7a8-2231-462c-9e24-580f72eed0a3/dusijetapafos.pdf
    • https://s3.amazonaws.com/kufazete/31676446311.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ccc3.bin
5d18333a3f16e4e4300678208648027f9aba98ebf36d2ff4d4d421c463b1c9d7
pdf-font-stream PDF embedded font (sfnt) at offset 0xCCC3 5436 bytes
font_01_sfnt_off0000df48.bin
30bfd69ed3d072bf258aa9e0f6b70dd26ce8ff9d5d1fc2d5475b25dcebb51d5b
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF48 10808 bytes