Malicious PDF — malware analysis report

Static analysis result for SHA-256 41bde7d1b7cd3376…

MALICIOUS

PDF

79.7 KB Created: 2021-06-24 00:41:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e1a5a04b5b293372df5840990912cfbb SHA-1: e8a5582b8dca486e7bb6997089e096c9ab14ba7b SHA-256: 41bde7d1b7cd3376fea3e827bb6c7add5ad85ed4c6be17e8ef9f4983906654c3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF document that was flagged by ML classifiers and ClamAV as malicious. It contains multiple embedded URLs, some of which point to suspicious PDF files hosted on compromised websites. The document body, though heavily obfuscated, suggests a lure related to a physics worksheet, indicating a social engineering attempt to trick the user into opening a malicious attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://elitestrategyglobal.com/wp-content/plugins/super-forms/uploads/php/files/a1f285fcce6dcddf4a5c7541beea85f1/favubelisol.pdf
    • https://glosunspa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607b52e2578ef---54644282490.pdf
    • http://www.loicadesacavem.pt/wp-content/plugins/formcraft/file-upload/server/content/files/160bd9414690bf---zitisawenu.pdf
    • https://independentmusicleague.com/wp-content/plugins/super-forms/uploads/php/files/308cca6d66a0c0003b440b733017511b/17715459449.pdf
    • https://www.abaco-engineering.it/wp-content/plugins/formcraft/file-upload/server/content/files/16096a459deca6---volusipatoxaviwu.pdf
    • https://socialchangefactory.org/wp-content/plugins/super-forms/uploads/php/files/82bd63d0035418257c36261b9e64be7a/wedapupawegumalobudur.pdf
    • https://mzr-avocats.com/buddha/ckfinder/userfiles/files/35202224344.pdf
    • https://clinicscrm.com/img/files/gijuwizedavirom.pdf
    • http://www.urbanwaterways.info/files/siwixibog.pdf
    • http://mesotects.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607c19ab50c39---10822202194.pdf
    • https://craftsmancuttingdies.com/wp-content/plugins/super-forms/uploads/php/files/fp4gl6sinqbhplhhadqfkvqgok/71531630598.pdf
    • http://uyaviation.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bd219320601---81902631396.pdf
    • https://kingwaterpure.com/ckfinder/userfiles/files/zegarabanewapawulafobo.pdf
    • http://mattstergamer.com/wp-content/plugins/super-forms/uploads/php/files/bda0ockh5kpfv10vepip0tsuqp/14053333371.pdf
    • https://joepromenshealth.com/wp-content/plugins/super-forms/uploads/php/files/5aa79a647709beb95696124fcf09296b/girowi.pdf
    • https://bbpartner.cz/userfiles/file/duwakokiruzejeron.pdf
    • https://aiaciran.org/cache/fck_files/file/sogunosap.pdf
    • http://hydrem.ru/images/file/bukatemajuviputipenof.pdf
    • http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bdda77b1a1d---regumojesitu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/FevRqgeaUVY/uplcv?utm_term=worksheet+on+force+and+laws+of+motion
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e13d.bin
ff509d18ce51934cc5c54a61092f3bf7aec5ff4b5ab8f96ae09c511f7397f32f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE13D 5428 bytes
font_01_sfnt_off0000f3ac.bin
d2f86ef0d6e8b5b65e5329019fdcca30ad486fca986e538ba6f2551a5d29d9c8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3AC 11772 bytes
font_02_sfnt_off00011bfb.bin
c8eae3229613ec76992f7fbad97dd690b5ba97dde82799fd50318f67dff80941
pdf-font-stream PDF embedded font (sfnt) at offset 0x11BFB 16232 bytes