Malicious PDF — malware analysis report

Static analysis result for SHA-256 421e86e4d8a58d08…

MALICIOUS

PDF

86.9 KB Created: 2021-03-24 16:43:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 95a05c9b421d5cd9d8134d7597f151e1 SHA-1: 6817b1988201ea304e36e7ea7f939c17a1540026 SHA-256: 421e86e4d8a58d084f1928589522ea7c3ebf41abf8ad51444f5de073e7a9ba36
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that redirects to a suspicious domain, likely for phishing or malware distribution. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest an attempt to exploit user interaction via a malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/123?utm_term=chandramukhi+tamil+songs+free++123musiq
    • https://cdn.sqhk.co/worijekegir/hDihRpm/15941848509.pdf
    • http://xezobofelupazat.22web.org/34573958350.pdf
    • https://cdn.sqhk.co/gogojelawov/TLiim0l/novitasavoboxod.pdf
    • https://cdn.sqhk.co/dabebasavus/hgjeXij/pet_paradise_georgetown_jobs.pdf
    • http://ketadiets.site/netgear_wgr614_software_free_downloadsetw4.pdf
    • https://cdn.sqhk.co/zapusukajev/jj9C8j1/12965171871.pdf
    • http://italiahot.space/nurifaw49i4.pdf
    • https://cdn.sqhk.co/vuzefegevo/Nriehbr/plague_inc_ultimate_board_game_scenario_guide.pdf
    • http://fobativ.mywebcommunity.org/teori_behaviorisme_dalam_pemerolehan_bahasa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4746be8d-db46-4489-8e1b-4c05e51ba542/38252221795.pdf
    • https://uploads.strikinglycdn.com/files/51096f0b-27c3-481c-894c-ab2ecaef9a97/what_is_bruce_lees_wife_doing_now.pdf
    • http://femasusatatovet.epizy.com/hindu_college_nagercoil_application_form_2018.pdf
    • http://zepurudevivo.rf.gd/45688366450.pdf
    • https://uploads.strikinglycdn.com/files/68bd8987-92d5-4392-93eb-d41629768f8d/whats_on_rising_sun_country_park.pdf
    • http://mepigijevu.rf.gd/d_link_dir_615_driver_download_free.pdf
    • http://zepizevut.atwebpages.com/89716025526.pdf
    • http://fuzunusizaxewo.rf.gd/cours_algorithme_informatique_debutant.pdf
    • http://bekelogamaju.rf.gd/angry_birds_go_hack_tool.pdf
    • http://tiwufuwivuvuf.epizy.com/giwaja.pdf
    • https://uploads.strikinglycdn.com/files/dc910764-980f-476f-942b-5eff82791402/judidima.pdf
    • http://xazoviwupudowol.rf.gd/uppababy_vista_double_bassinet_on_top.pdf
    • http://zemoxatovasoga.rf.gd/medical_fitness_certificate_format_for_leave.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001158f.bin
f1894b3875e1ee5ff151f9d28faae24425a14ce835dfaf8f67dc7934dea32f28
pdf-font-stream PDF embedded font (sfnt) at offset 0x1158F 5764 bytes
font_01_sfnt_off000128fc.bin
20027d3d995973a46cc98980d14c57977970f97477d2e34d4de990101e7b1510
pdf-font-stream PDF embedded font (sfnt) at offset 0x128FC 10872 bytes