Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f70ecd77bd9974e…

MALICIOUS

PDF

87.1 KB Created: 2021-04-05 23:43:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7d6c3ded0df47226eb0d98bff5a1768e SHA-1: bf1953c389dc50d5ade61a85806479dbef422297 SHA-256: 3f70ecd77bd9974e63e0a5065833a5ed12cd7e8f14cc3163f56b399575dd45b2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to redirect users to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=dichotomous+key+examples+for+candy
    • http://zekofurul.iblogger.org/55050711313.pdf
    • https://cdn.sqhk.co/xavipinav/egiidwo/jefavafipofitokivisoweb.pdf
    • https://cdn.sqhk.co/koditisalupe/jdUTic4/popular_love_songs_of_the_60s_and_70s.pdf
    • http://mitipuwade.22web.org/xudumopejajiwi.pdf
    • http://help-mediasupport.com/best_music_rocket_leaguecqifz.pdf
    • http://alisabor.design/clothes_activity_worksheetk3ntw.pdf
    • https://cdn.sqhk.co/dabebasavus/XhflLLc/rayman_fiesta_run_android_apk_free_download.pdf
    • http://wspring.space/46299251985tgqb9.pdf
    • http://ifeelgood.club/powerpoint_temalar_indir_gezginlerggrfx.pdf
    • http://selectgetc.top/apc_550_batteryi6czx.pdf
    • https://cdn.sqhk.co/janonaset/0zhbnO7/lanawikowasozi.pdf
    • http://meetcabinets.xyz/209939233085gp4a.pdf
    • https://cdn.sqhk.co/zamupefa/oVgg1ig/dubigixodobu.pdf
    • http://gavuzusim.iblogger.org/784726589.pdf
    • http://goodsfor.life/achyutam_keshavam_krishna_damodaram_lyrics_ringtonetl8vv.pdf
    • http://leomannapov.com/42378631974hm9z3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://xigesema.epizy.com/brady_bmp21_plus_label_printer_starter_kit.pdf
    • http://telenusu.epizy.com/fitbit_inspire_hr_product_manual.pdf
    • http://rikulovesemura.rf.gd/33612975176.pdf
    • https://uploads.strikinglycdn.com/files/fa5bcba6-a9be-40f9-9d64-3025e82d2868/dir_868l_review.pdf
    • http://fobiwuna.epizy.com/musclepharm_workout_program.pdf
    • https://uploads.strikinglycdn.com/files/f1da5a72-94d5-4301-b250-dd26172d1e32/90880479640.pdf
    • https://uploads.strikinglycdn.com/files/b4f7a5a0-d9ad-4c00-92ab-f89bf28a09ff/635849335.pdf
    • https://uploads.strikinglycdn.com/files/86150195-943f-40c9-a3df-f464aa4c4b4c/what_are_the_linux_commands_that_helps_to_find_files.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef7a.bin
a606a6dede3b99472d2ac97761204782646b5f75106b48d1abccbe9a99ca9a4c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF7A 6440 bytes
font_01_sfnt_off0000ff6e.bin
8058fdbec79047dda22f142ac1875dbe79ae0bd8bc8781ff64fc586500631c38
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF6E 5628 bytes
font_02_sfnt_off0001127d.bin
81152bd92afad6ce9479a26a87055fbe8cb7e3ae8c2d3989dfefa1bb25f0c09e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1127D 11300 bytes
font_03_sfnt_off0001393e.bin
bcfecb9fde4b74e4a2b692e15caf305b2988a1cfe4c6386614002e38d35feb86
pdf-font-stream PDF embedded font (sfnt) at offset 0x1393E 16168 bytes