Malicious PDF — malware analysis report

Static analysis result for SHA-256 545a2830fd22aa1e…

MALICIOUS

PDF

79.9 KB Created: 2021-04-12 05:35:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-29
MD5: 4e16d8cbbd0e75c2fd61e1cdb098ce60 SHA-1: c94725aa7b10e5d1dde817af9696ebef7ac80522 SHA-256: 545a2830fd22aa1e3154e8e726d07b3bba8700764dfa19384f2bef0fba86966b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The PDF contains embedded URLs, one of which is flagged as benign, but others are unknown and potentially lead to malicious content. The document body is heavily obfuscated, but the presence of embedded URLs suggests a phishing or malware distribution attempt, likely initiated via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.enwidth.com/sites/default/files/webform/resumes/79062027218.pdf In PDF document text
    • https://www.visitsavannah.com/sites/default/files/webform/mubojezelu.pdfIn PDF document text
    • https://vectorcorp.net/sites/default/files/webform/resume/92207600326.pdfIn PDF document text
    • https://europa-ts.ru/sites/default/files/webform/81905598419.pdfIn PDF document text
    • http://klm3fg.grhosting.cz/sites/default/files/webform/files/40110328039.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/kepasibadugemefobovabo.pdfIn PDF document text
    • https://www.jsif.org/sites/default/files/webform/95147346690.pdfIn PDF document text
    • https://www.natsihwa.org.au/sites/default/files/webform/25680057182.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/sudelo.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/nakevatekiviva.pdfIn PDF document text
    • https://www.woonsocketri.org/system/temporary/webform/51053607868.pdfIn PDF document text
    • http://russian-ice-spb.ru/sites/default/files/webform/files/97818084314.pdfIn PDF document text
    • https://vectorcorp.net/sites/default/files/webform/resume/30106672217.pdfIn PDF document text
    • http://klm3fg.grhosting.cz/sites/default/files/webform/files/56601188302.pdfIn PDF document text
    • http://oaklandchildcare.org/sites/default/files/webform/veser.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/28961662769.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://feedproxy.google.com/~r/Uplcv/~3/FevRqgeaUVY/uplcv?utm_term=the+new+successful+large+account+manPDF link annotation
    • https://printandmail.princeton.edu/system/files/webform/zixulupuritijidegebi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed77.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED77 5172 bytes
SHA-256: 526a03feac2407eb905c9c19669b6c6c40aad61db7997c605e811636898f647f
font_01_sfnt_off0000fef1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFEF1 11008 bytes
SHA-256: 89e13a491df500a7dbe8ea99735e9150239c6acf231bd8ae29b624b09788af74
font_02_sfnt_off0001247b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1247B 4324 bytes
SHA-256: 7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71