Malicious PDF — malware analysis report

Static analysis result for SHA-256 54dfd9a7559202ee…

MALICIOUS

PDF

82.0 KB Created: 2021-03-09 12:54:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2ed8028f0acfa818908218b732320c58 SHA-1: 256ea0ade7c7e4dbf4f93b02d59726d14422a145 SHA-256: 54dfd9a7559202ee8c16297b83c92f5799c705fd76b66de586ca8ce11f49e3aa
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, likely intended for phishing or malware distribution. ClamAV detection and ML classification strongly indicate malicious intent. The presence of multiple external URLs further supports the attack pattern of luring users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=kaufland+let%25C3%25A1k+ostrava+pdf
    • https://baliwiwun.weebly.com/uploads/1/3/1/3/131380001/jedetebubotob.pdf
    • https://cdn.sqhk.co/kerutadit/iajd8fw/dark_hd_wallpapers_for_laptop_download.pdf
    • https://cdn.sqhk.co/vujenibolo/HijJicR/space_pirates_vr_oculus.pdf
    • http://jajifejeda.22web.org/sync_microsoft_outlook_calendar_with_android_phone.pdf
    • http://dehydratedoriginalgoodness.com/baaghi_movie_videoc0jse.pdf
    • https://dibigisilob.weebly.com/uploads/1/3/1/6/131607467/zemateweg_wibobi_momodamomub.pdf
    • https://cdn.sqhk.co/ripowusaro/ftifgib/40770734390.pdf
    • https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/6712532.pdf
    • http://tizezs.xyz/free_service_agreement_template_nzfut37.pdf
    • https://cdn.sqhk.co/kujexelorite/hgjeTgf/cheap_walk_in_nail_salon_near_me.pdf
    • http://adv-workshop.site/free_printable_accounting_ledger_templaterpccc.pdf
    • https://cdn.sqhk.co/vunelebu/uhhywje/nudaregopifukidix.pdf
    • http://bigchance.pw/zitirejas8qaqd.pdf
    • https://dupomogorudo.weebly.com/uploads/1/3/4/5/134595760/mevafunev.pdf
    • http://terem.space/40510242596bqr5c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f2573539-e81d-4715-b115-5202d0cc8e03/sinners_in_the_hands_of_an_angry_god_by_jonathan_edwards_analysis.pdf
    • http://vamanufa.rf.gd/nigovuzizepefeligutuxosu.pdf
    • https://uploads.strikinglycdn.com/files/22375ac3-5afb-4ed3-8cbe-2d840e0439ac/losakawaka.pdf
    • https://uploads.strikinglycdn.com/files/3543051b-902f-48ad-a748-9ae4ef4d96b4/the_vampire_diaries_merch_etsy.pdf
    • http://pafojamivorizim.epizy.com/how_to_set_time_on_echo_wall_clock.pdf
    • https://uploads.strikinglycdn.com/files/11e9cddf-2426-4166-b8d8-3284e9adfae3/xatupegixulefajabilep.pdf
    • https://uploads.strikinglycdn.com/files/53987fc4-2ab7-4f99-aebd-dceab8fb0c99/how_much_do_accident_investigators_earn.pdf
    • http://jogulele.epizy.com/85294267116.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ffb7.bin
7bc8d4bf66707cb000a802cae2b135c0d3f9d6efd4afa3413223d0dddfcb7e05
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFB7 5364 bytes
font_01_sfnt_off00011184.bin
db2e6f2c4a9674ed80fc46ffeaeaad6e5a50ddd310c20bbcecaacf8805170dca
pdf-font-stream PDF embedded font (sfnt) at offset 0x11184 12816 bytes