Malicious PDF — malware analysis report

Static analysis result for SHA-256 577b8097268380f6…

MALICIOUS

PDF

100.5 KB Created: 2021-03-13 21:58:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 583e74ef2b9e7c43fdc60b5192b50619 SHA-1: 581ce22e1a6e130530c111f82b01b341b7ed5922 SHA-256: 577b8097268380f6d79278ecd5c55a3cfde5ba448d86d6a64ee4ed4599a25158
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a malicious domain, indicating an attempt to redirect the user to a phishing or malware distribution site. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware delivery. No scripts were extracted, but the presence of external URLs and the document's nature suggest it's part of a phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=theme+2+development+and+interaction+of+cultures
    • http://wwnews.site/radioactive_dating_game_worksheet_answers6a39g.pdf
    • https://cdn-cms.f-static.net/uploads/4412154/normal_6014922359833.pdf
    • http://the-english-temple.com/echo_spot_instruction_manual92rje.pdf
    • http://lobikekifeviwo.iblogger.org/pomaxelebabolabuz.pdf
    • http://egrn-order.online/5667503968774m9j.pdf
    • https://static.s123-cdn-static.com/uploads/4411681/normal_5fffbdafafbde.pdf
    • https://static.s123-cdn-static.com/uploads/4449973/normal_5fcfaef6cd498.pdf
    • http://getplafond.xyz/chaliya_chaliya_song5hg8h.pdf
    • http://lynciguest.com/474299688595ubl1.pdf
    • https://static.s123-cdn-static.com/uploads/4494433/normal_5fee9d073f290.pdf
    • https://cdn-cms.f-static.net/uploads/4405674/normal_5fe92a003ce68.pdf
    • https://static.s123-cdn-static.com/uploads/4415526/normal_5ff7132550022.pdf
    • https://cdn-cms.f-static.net/uploads/4449776/normal_600bfd7a52cfa.pdf
    • https://static.s123-cdn-static.com/uploads/4479675/normal_5fcce12cf16b1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://vidofebusezix.epizy.com/23239304421.pdf
    • https://uploads.strikinglycdn.com/files/a4aa51cc-e4f2-437c-bd41-fc4f8e892434/navy_seal_training_website.pdf
    • https://uploads.strikinglycdn.com/files/196e78ad-e88c-47e4-8dab-75ed2484f7bb/dcs_su-25t_campaign.pdf
    • https://uploads.strikinglycdn.com/files/7342a6a0-0ef0-4952-843f-c4dd441cc7ad/civil_engineering_diploma_books_in_hindi.pdf
    • http://voratibix.rf.gd/48191629659.pdf
    • https://uploads.strikinglycdn.com/files/ccc221b2-a45c-403e-91f3-1052c3ca9af4/7613219129.pdf
    • https://uploads.strikinglycdn.com/files/83ed07b2-8ee2-41b5-b102-c11e22cb0915/oxford_history_of_the_united_states_complete_set.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010621.bin
e0157ba8137bdf890a3c87143ec814ffaf9a5dbd787a6fc891054bdc0328e2c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x10621 5536 bytes
font_01_sfnt_off000118d2.bin
4d8825eeb315b5ada8835b704af2c3d1e108ee213ac7032f8130a265e0e7b94e
pdf-font-stream PDF embedded font (sfnt) at offset 0x118D2 15656 bytes
font_02_sfnt_off000144d8.bin
7520c18c1ef5787e705419d51f822cb2e4f3a6153474b6c7e7b25119dd6b9192
pdf-font-stream PDF embedded font (sfnt) at offset 0x144D8 11408 bytes
font_03_sfnt_off00016bf4.bin
95d855f69192139b793117b98fb1d980f6a6f45f3f8badb21d54032bf3ce2f9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x16BF4 16408 bytes