Malicious PDF — malware analysis report

Static analysis result for SHA-256 59bec2e35697654c…

MALICIOUS

PDF

83.8 KB Created: 2021-03-20 09:20:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bdd68a0029f7f0c972cfb415291ceb13 SHA-1: 7cbe29343e2f1dc00e23b53f1b6a6c76b356d8f5 SHA-256: 59bec2e35697654c28398076f64fd1e1bd70fc2a1ede50c6a0f48d49a3774ab2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of external URIs, specifically those with unknown reputations, suggests the document is designed to redirect users to potentially harmful content. The document body, though heavily obfuscated, contains keywords related to 'syllabus' and 'download', reinforcing a phishing or social engineering lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=bank+po+syllabus+pdf+free+download+2020
    • http://mail-autoscout24.net/792917872384ggwl.pdf
    • http://fb-copyright-help-from.com/26356231302m8yds.pdf
    • http://wusozupu.mypressonline.com/79056552610.pdf
    • http://ifeelgood.club/what_does_double_down_mean_slangj6jve.pdf
    • http://kindraretterath.com/ssangyong_korando_service_manualacjhs.pdf
    • http://arthromedro.xyz/582963585623eaaq.pdf
    • http://vorecan.fun/biroxumen935rq.pdf
    • http://nafepuzemobir.sportsontheweb.net/can_you_pair_two_remotes_to_roku.pdf
    • http://biweekamnf.com/saxanarumedrwzjo.pdf
    • http://foyou.store/bonivamutelefub0yte.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/meludav/former_capital_city_of_west_germany.pdf
    • https://s3.amazonaws.com/jolituzoji/how_much_does_a_mercury_25_hp_weight.pdf
    • https://s3.amazonaws.com/fajujiju/saxusupinopivulijotax.pdf
    • https://s3.amazonaws.com/webipejonavuv/xekewilomikorisopugoda.pdf
    • https://s3.amazonaws.com/zolerazowubow/free_newborn_photography_posing_guide.pdf
    • https://s3.amazonaws.com/gajakelegeza/casual_employee_termination_letter_sample.pdf
    • http://pojozija.onlinewebshop.net/harbor_breeze_ceiling_fans_installation_instructions.pdf
    • https://s3.amazonaws.com/gofilafixu/aprendizajes_clave_primaria_tercer_grado.pdf
    • https://s3.amazonaws.com/donarepemi/90164397282.pdf
    • https://s3.amazonaws.com/xutomoxu/androidx_toolbar_style.pdf
    • https://s3.amazonaws.com/muwemivumazulax/32301542745.pdf
    • https://s3.amazonaws.com/zagubip/tovoredutad.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f42b.bin
b05c0a2ec1bd77a1a71fee0c650ee2975992c56aa96346d7577d621a4ea8eaf5
pdf-font-stream PDF embedded font (sfnt) at offset 0xF42B 5756 bytes
font_01_sfnt_off000107f0.bin
68e0b4912fc60de8f2275c5959b44fd9415cb38b72762fabb19b0aa248899aca
pdf-font-stream PDF embedded font (sfnt) at offset 0x107F0 10524 bytes
font_02_sfnt_off00012c1d.bin
e93acd332f5893643511f4cefd38969ad5c744ad1b08842a788b6be7d277dd15
pdf-font-stream PDF embedded font (sfnt) at offset 0x12C1D 16204 bytes