Malicious PDF — malware analysis report

Static analysis result for SHA-256 420ae31c8be647d6…

MALICIOUS

PDF

81.2 KB Created: 2021-03-14 04:49:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 17c4e1ccd40cfc6bb9110c3f1a8a898f SHA-1: a3210d2f78be49b10307bcb1299e3f03870e19dc SHA-256: 420ae31c8be647d61152d8ba46e3355f2e93e51f8da9bf96e318a2887e40ea47
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by multiple heuristics and a machine learning classifier as malicious. It contains an embedded URI pointing to a suspicious domain, which is likely used to deliver a secondary payload or conduct phishing. The presence of PDF-specific heuristics and the ML classification strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=excel+vba+worksheetfunction+index+match
    • http://snapchat-alert.com/xagijejugarorilfwm1k.pdf
    • http://bnl-jobs.com/minecraft_app_uptodownkgopv.pdf
    • http://fullcreditreport.info/global_carbon_project_report_2017o8ffr.pdf
    • https://cdn-cms.f-static.net/uploads/4449602/normal_601db1d5ecd33.pdf
    • http://zigamesixeviru.22web.org/bio_data_format_in_word_for_job.pdf
    • https://static.s123-cdn-static.com/uploads/4488100/normal_5fd0673e82112.pdf
    • http://persequen.com/nikejitekikgnuic.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/a09a2e9c-e1d3-438c-8d9a-0bf728a89806/what_is_the_omnibus_reconciliation_act_of_1987.pdf
    • https://s3.amazonaws.com/luramamelolem/25702114458.pdf
    • https://s3.amazonaws.com/divelatoxa/weather_report_of_kolkata.pdf
    • https://46a1ac71-481d-4a85-b709-d40f3a189542.filesusr.com/ugd/143c98_b2bddc8002ce434ea2aad8d39e075d8a.pdf?index=true
    • http://jemaxib.rf.gd/3540519249.pdf
    • https://80c8fd16-4cf8-4f9f-b52b-d6c956df8f3b.filesusr.com/ugd/1a94e8_d4729e280da34199aa316efcec27b512.pdf?index=true
    • https://s3.amazonaws.com/farowug/blender_2._78a.pdf
    • https://uploads.strikinglycdn.com/files/911d1cad-d1bf-4e94-bdf0-16399d163d1b/81264221049.pdf
    • https://75a697d3-84f0-44cf-bab9-f05e37020c50.filesusr.com/ugd/7c3584_eaf0aff306b74877bdfacd360be9b8a4.pdf?index=true
    • https://uploads.strikinglycdn.com/files/40b35969-ac48-445c-aae3-9d23efa0939a/cuanto_equivale_un_metro_cubico_en_cm_cubicos.pdf
    • https://s3.amazonaws.com/zozuxukoxo/bootstrap_template_maker_software.pdf
    • https://def26600-86c9-4442-a738-094ddf2992d1.filesusr.com/ugd/eb5a6a_a2532b95cb7d4b3da9d7c4bb39db16b1.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fcc8.bin
fe423ce07dfea947f3cae195e63b2263c18f951e4490f426aeaeb7c060e7bc44
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCC8 5644 bytes
font_01_sfnt_off00010fed.bin
d3cae76ea6617dab66b8c8f99f53d62899f4b551a2ae26157b91d127c76aa14a
pdf-font-stream PDF embedded font (sfnt) at offset 0x10FED 11632 bytes