Malicious PDF — malware analysis report

Static analysis result for SHA-256 5de1e9f6315e92f5…

MALICIOUS

PDF

62.1 KB Created: 2021-05-06 23:15:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0b6a93f59d5f38870820a9e44d7e5284 SHA-1: 861ee745e92222f81ec80277ca9e7d4f827fc8e8 SHA-256: 5de1e9f6315e92f52f3a2b0625edb63b649ede4191346dc61f29b1b287b25695
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a PDF that contains embedded URLs, one of which is flagged as potentially malicious by ClamAV. The ML classifier also flagged the PDF as malicious. The document body, though heavily obfuscated, suggests a lure related to 'sheet music', likely to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8016

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.sidertest.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607006ea14e07---mugopavopezibodoja.pdf
    • https://medprobr.com.br/wp-content/plugins/super-forms/uploads/php/files/454778393b0dcb1decec0b81c75506da/98246710641.pdf
    • https://massagetheory.ca/wp-content/plugins/super-forms/uploads/php/files/1a1c97dfbafca38705b50cc90b626061/navudikakesadan.pdf
    • http://www.yourhealthyourchoice.org/wp-content/plugins/formcraft/file-upload/server/content/files/160719a868deca---nomiva.pdf
    • http://lawcab.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160762009ab08e---18800861975.pdf
    • http://www.ebsjosepirosamaria.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093af5e909fc---60104823958.pdf
    • http://ivepe-elearning.gr/assets/UserFiles/mainHome/file/lipububokokijesutugonuf.pdf
    • https://www.acetechnology.co.in/wp-content/plugins/super-forms/uploads/php/files/q0e1h6efrdfm8jnaull2hgkj6f/fijivenudarikikuduniduted.pdf
    • https://rmdschoolandcollege.com/wp-content/plugins/super-forms/uploads/php/files/2q8h2ablbiavp49mlgvj984mf7/98898284068.pdf
    • http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074275981490---zixufoxubatetoburutere.pdf
    • https://www.helpagesl.org/wp-content/plugins/formcraft/file-upload/server/content/files/160943d03a3734---78959222273.pdf
    • https://awlights.com/wp-content/plugins/super-forms/uploads/php/files/e6f84464d2106efc2f0011555bbf9d0c/bojeg.pdf
    • https://f1com.ge/wp-content/plugins/super-forms/uploads/php/files/44582a0ba9d8e845c8c224b023fb7c20/15987345041.pdf
    • https://www.sussexweddingservices.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1609026cade35f---foxifizu.pdf
    • http://www.driftime.ee/wp-content/plugins/formcraft/file-upload/server/content/files/160908d2b81585---58880876853.pdf
    • http://www.rolstoellift.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cfeb5c400b---31462480779.pdf
    • http://subventionsbetrug.de/wp-content/plugins/super-forms/uploads/php/files/uup70k1gut2cfcpq8sluia035l/rimuziga.pdf
    • https://cffcommunications.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/1608668446ddfd---4818407151.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=pink+panther+alto+sax+sheet+music+easy
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cde7.bin
18416b34c50dfe8924fa05d8ebbb686b5526107883b236f7d7cc3c24492faf51
pdf-font-stream PDF embedded font (sfnt) at offset 0xCDE7 5408 bytes