Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ff856e2dcf13da9…

MALICIOUS

PDF

85.5 KB Created: 2021-03-20 16:02:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2450c5eef153f5353e63262e93ce8374 SHA-1: 2c933df918a03ecddad828ccd77542c9d48ecbdc SHA-256: 3ff856e2dcf13da963b1c9f7bd4b0f5dbf880a73b012eebe47b22eb29c16d95f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains an embedded URL that, when accessed, likely leads to the download of a malicious file. The document body's content and the presence of multiple suspicious URLs suggest a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=hacked+pokemon+go+apk+ios
    • http://ndfnasg.xyz/81106592772kwgj9.pdf
    • http://xajoraxi.22web.org/jojixobinomikorep.pdf
    • https://fojevatiseme.weebly.com/uploads/1/3/4/4/134400043/2165574.pdf
    • http://paganel.world/nolemakunufofewotiv.pdf
    • http://jugixemetofun.22web.org/tatogekevan.pdf
    • http://luminar4-download.xyz/hollow_knight_the_huntergydzj.pdf
    • http://blockingscenery.com/937760727639qzr8.pdf
    • https://vubenazago.weebly.com/uploads/1/3/4/3/134357699/c847e91e37.pdf
    • https://vitigamonewus.weebly.com/uploads/1/3/1/4/131406732/tagepemokewifoz.pdf
    • http://fabanefefori.22web.org/graphing_rational_functions_kuta.pdf
    • http://lnstagramlivesupportcenter.com/shooting_games_for_pc_under_1gbjxcew.pdf
    • https://cdn.sqhk.co/jeporikate/0ihdShc/convergent_evolution_definition_science.pdf
    • https://cdn.sqhk.co/kawiwitifa/Ld9ifha/26348649494.pdf
    • https://cdn.sqhk.co/feziwetesene/galWI3V/youtube_video_downloader_chrome_addon.pdf
    • http://popubim.iblogger.org/13768673386.pdf
    • https://cdn.sqhk.co/petebeki/ijhs05Y/my_home_design_dreams_free_online.pdf
    • https://cdn.sqhk.co/pugusomimoro/djcHLij/football_championship_2022_world_cup_place.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://kakoxoduruze.epizy.com/weekly_meal_planner.pdf
    • http://rudikagonon.rf.gd/alexander_pope_as_a_critic.pdf
    • https://2ddedb0e-b7b0-41c9-a8bc-c018bd0e6e4c.filesusr.com/ugd/70094d_20569eddee644c178fc8353943c6793f.pdf?index=true
    • http://sewokamituga.rf.gd/career_development_in_hrm.pdf
    • https://b03e51a8-7171-48c0-94d6-e4c032e6f37f.filesusr.com/ugd/9421c8_5d97c23beebb406a9001c855de132929.pdf?index=true
    • https://3c86e5df-9a55-47dd-9d5b-c207b25ec6cd.filesusr.com/ugd/72bf36_042ea00db2d24b89b2f379f5d1d11592.pdf?index=true
    • https://b54663a3-ff9d-4122-b75c-69b71428c9b0.filesusr.com/ugd/cfa91a_222efc273aae4707a425568df1c92229.pdf?index=true
    • http://xomezotesojopuv.epizy.com/42664147944.pdf
    • http://pizibopiro.epizy.com/stephen_king_firestarter_movie_cast.pdf
    • http://degepedafapuf.epizy.com/avermedia_lgp_lite_drivers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010eea.bin
89cda3e94c66346d6e6be0c9131ad930f9e3c02e0e4b6044565d4be512ab8491
pdf-font-stream PDF embedded font (sfnt) at offset 0x10EEA 5292 bytes
font_01_sfnt_off000120da.bin
9a2fb5c9464638307baf787541c0769da20cb61f03cb960454b9d451e3e181aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x120DA 11836 bytes