Malicious PDF — malware analysis report

Static analysis result for SHA-256 441f6f3cdd47a64d…

MALICIOUS

PDF

91.9 KB Created: 2021-07-04 17:09:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: d418ff3054dccb4f500dd8d9a1e2d798 SHA-1: 4238cf1d8490d858075bbdb11cb1bb03e4d5bbdb SHA-256: 441f6f3cdd47a64d7fc813e571042be27d2641a1f65d0250f02e3938ec73f9bc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs suggests a phishing or credential harvesting attempt, or a lure to download additional payloads. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of common malware delivery techniques.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9835

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://assurancemauricie.com/wp-content/plugins/formcraft/file-upload/server/content/files/160756b95761ef---dabukuv.pdf
    • https://thewaves.net/wp-content/plugins/super-forms/uploads/php/files/auufq7psfr9h3opqskd96grng3/29251079404.pdf
    • http://nuraski.pl/wsg/userfiles/19583651327.pdf
    • https://traveletrust.com/basefile/traveletrustcom/files/jejaxabulopunemixek.pdf
    • https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ada07712ed8---91049889505.pdf
    • http://ednak.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080966d702a5---daketobujo.pdf
    • https://tucsonhomewindowtint.com/wp-content/plugins/super-forms/uploads/php/files/44b872ba5c55f1e63c1115cbbf167157/36253200206.pdf
    • https://qualitylightsolutions.com/wp-content/plugins/super-forms/uploads/php/files/69984f95207e11576235acb8169d31ee/95879178656.pdf
    • https://fruzsiflame.hu/userfiles/file/28077117480.pdf
    • http://www.morenoroofing.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085686f8c795---91878975926.pdf
    • https://chp-travel.ir/data/file/80852147285.pdf
    • http://sakirnoopo.ru/wp-content/plugins/super-forms/uploads/php/files/4009e9c8d9f6fffc7790b0c28d0eddd8/34577282041.pdf
    • http://exosportsante.fr/ckfinder/userfiles/files/78529023610.pdf
    • http://aksaaydinlatma.com/img/editor/image/file/rowabiliwimenokogup.pdf
    • https://bdaudit.ro/userfiles/file/43793709287.pdf
    • http://comicpapyrus.com/wp-content/plugins/super-forms/uploads/php/files/3c55ace6c96fb62510d94979884b1647/rizofuvuzugemutozu.pdf
    • https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/207abaaec33379ff9bf98840f3ddd185/8712864727.pdf
    • http://www.meglobalinc.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/1606fc3b84b86e---vobid.pdf
    • https://anpheatingandac.com/nbloom/fckuploads/file/8492730318.pdf
    • http://www.photobreak.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1606f4f99a00b4---videfuxit.pdf
    • http://ankurgroups.com/userfiles/file/47520698436.pdf
    • http://counterreaction.net/wp-content/plugins/formcraft/file-upload/server/content/files/1606d91bd03125---sugefojusazegibi.pdf
    • http://tznjl.com/userfiles/files/61994306206.pdf
    • https://lifecareproduct.in/ckfinder/userfiles/files/vobexubewalusapewixin.pdf
    • https://heatingboiler.ca/fck_upload/file/80957975483.pdf
    • https://wrd13.com/force/file/72129542309.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=i+believe+in+you+meaning
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000104fe.bin
940130225e3627e1f25c9cd4a205591acb86829840b8e6fb12a96c07f8cd3433
pdf-font-stream PDF embedded font (sfnt) at offset 0x104FE 16944 bytes
font_01_sfnt_off00013126.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x13126 16792 bytes
font_02_sfnt_off0001493d.bin
bc4bf97a8d78d8c8f94d6253d8eb73f6f69b5499631e6a57a03f113aa3f1c2f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1493D 10456 bytes