Malicious PDF — malware analysis report

Static analysis result for SHA-256 57bb35ad552b3874…

MALICIOUS

PDF

214.9 KB Created: 2021-03-17 01:45:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 34eb93b3c6d1031462249b32854edb20 SHA-1: 99bf0b9cd73b4acd29df53958650b3e1750f5972 SHA-256: 57bb35ad552b3874b72bafd442f6fb7937b371f0a4b14c5767b7a61375c3dc63
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest it's designed to exploit users by masquerading as a legitimate document to redirect them to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9771

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=bangalore+map+area+wise+pdf PDF link annotation
    • http://galabogenezoso.getenjoyment.net/character_traits_worksheet_3rd_grade.pdfIn PDF document text
    • http://xadexawufomovi.sportsontheweb.net/86935204150.pdfIn PDF document text
    • http://baliferifopiz.mypressonline.com/vapomu.pdfIn PDF document text
    • http://vugijow.iblogger.org/que_es_un_catalizador_en_biologia.pdfIn PDF document text
    • http://blog-millionaire.buzz/730910095857hn6y.pdfIn PDF document text
    • http://kiwenalod.medianewsonline.com/lonobivogezuz.pdfIn PDF document text
    • http://galabogenezoso.getenjoyment.net/matevu.pdfIn PDF document text
    • http://lijonotogi.scienceontheweb.net/22466046924.pdfIn PDF document text
    • http://fexevewuli.mypressonline.com/the_book_thief_full_book_download.pdfIn PDF document text
    • http://sifaritube.sportsontheweb.net/pdf_to_word_converter_online.pdfIn PDF document text
    • http://walletelectrum.buzz/lefemutegakijisimedapazeh9uo.pdfIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/livivuvuwugeb/48949306280.pdfIn PDF document text
    • https://s3.amazonaws.com/fakuguvil/vevafutuwil.pdfIn PDF document text
    • http://muvipifipu.rf.gd/86132412182.pdfIn PDF document text
    • https://s3.amazonaws.com/fulazelof/go_go_scooter_battery_box.pdfIn PDF document text
    • http://lunijikujapike.epizy.com/perufawubunufobimo.pdfIn PDF document text
    • http://bixifededas.rf.gd/wujemobuwagamiwafinav.pdfIn PDF document text
    • https://s3.amazonaws.com/pizexopenaxu/tabebazorusuwurepazefiriw.pdfIn PDF document text
    • https://s3.amazonaws.com/sizabo/bpsc_mains_history_question_paper_2018.pdfIn PDF document text
    • https://s3.amazonaws.com/matogapibelifiv/ionic_bonding_properties_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/wixanarer/wd_2tb_my_passport_wireless_ssd_external_portable_drive.pdfIn PDF document text
    • http://xarozimazog.rf.gd/add_drop_down_list_in_word_template.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0002ea14.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2EA14 3548 bytes
SHA-256: aea9b0a7ea9dcab0806e5bd45ce1bc00ba6b8710eabcdc8987c6836e75674857
font_00_sfnt_off0002d86e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2D86E 5208 bytes
SHA-256: 53e92a4ab0fb80ca49893d37e4d758adc5ef456ad4a5ae2ea6655b11ac0319af
font_02_sfnt_off0002f82b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2F82B 15700 bytes
SHA-256: f34ef820bd69f72e030bc1e6f28f25b6d1b6c070c760481341676a0131391dbf
font_03_sfnt_off00032949.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x32949 16164 bytes
SHA-256: ebd2804bff382343e08f6a42dc45f69f4e794c08b23908ae60ba78ededae74b1
font_04_sfnt_off00033e61.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x33E61 4324 bytes
SHA-256: 7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71