Malicious PDF — malware analysis report

Static analysis result for SHA-256 4d03b9a2fc4d9803…

MALICIOUS

PDF

182.3 KB Created: 2020-11-24 04:35:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: 67767b68d2df580a842c8a79737cf442 SHA-1: 920a77ed82c9d6d64b6f7794ee7dd817c6b057a8 SHA-256: 4d03b9a2fc4d98032cd1e41e8203a8ccf6b18f1e6ffcb35506e96dfa558de90c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/strik?utm_term=corioliskraft+physik+formel PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4373788/normal_5f89d0a72d0e5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4491433/normal_5fb8e1a981798.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455658/normal_5fb7b9396bdad.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365655/normal_5f9a6836e1a55.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4461498/normal_5fbc3b9627c4b.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/memul/the_sandman_neil_gaiman.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/55adc88e-93b9-4930-86be-bf160c46c06d/17895459227.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fd635f06-4e5f-4a11-9164-4e38d48845a9/vabumizisabigisaxojusogo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c212f6df-72fc-43af-a0c5-e19e88585299/21882374053.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/152a09c2-3e3e-4d37-a895-a1e9caa03fcc/jufowizus.pdfIn PDF document text
    • https://s3.amazonaws.com/neviwove/11_class_admission_guidelines_of_kendriya_vidyalaya.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/350af98a-b49a-4914-b589-a8534b56ae0b/wen_air_filtration_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4f5b3199-f17e-45a4-9315-71b8c6b59355/boremuzizegik.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e96bb67c-9101-4634-9919-9a8d809e83d0/5054615773.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/91575060-a7c3-4af8-8f91-9294394cf02c/comparing_and_ordering_dissimilar_fractions_worksheets.pdfIn PDF document text
    • https://s3.amazonaws.com/bolovopizonuki/58237587815.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd04c7f9-5cff-454d-9e23-c612e8b86dd2/yamaleela_telugu_audio_songs_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00026580.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x26580 5212 bytes
SHA-256: 63e654d12cdff36d6578277d271bd0f0ad5d229a1179557dcc42085dc2b24a48
font_01_sfnt_off000276d5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x276D5 6300 bytes
SHA-256: 33e079d314e8ac6127b1e3ef6c589fac86ee1747e1198796ea12012fa2a002c7
font_02_sfnt_off0002862b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2862B 14144 bytes
SHA-256: 036e1a9a649abb2c6e22257f95f49402725b821585e31ec5f93eaa942a4333d4
font_03_sfnt_off0002b4ac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B4AC 16240 bytes
SHA-256: f29ad2755613249f54ebbdc3b66535cc085f284a4badaff486042ff4aa3e84db