Malicious PDF — malware analysis report

Static analysis result for SHA-256 617000b9a7bd4f0f…

MALICIOUS

PDF

71.7 KB Created: 2021-05-14 04:42:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 139166fcb4beb93817f91485f1b20d25 SHA-1: dba24f4e54130865d49096f405e9110eb8ba4990 SHA-256: 617000b9a7bd4f0f4a4f427879e5ff61395641e41b15e209fafcd5e6db438585
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains obfuscated text that appears to be a lure for downloading software, specifically mentioning 'Autocad 2014 with keygen free'. The presence of numerous embedded URLs, many pointing to file-hosting services, suggests an intent to redirect users to download malicious payloads. ClamAV detection and ML classification further support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.adler-leitishofen.de/wp-content/plugins/formcraft/file-upload/server/content/files/160784b7e60e57---7853999250.pdf
    • https://alice-immo.com/userfiles/file/pigazeta.pdf
    • http://baharemadinah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e980c9568c---veguwirazafufen.pdf
    • https://alphacleanwashing.com/wp-content/plugins/super-forms/uploads/php/files/51263828f69aac76bcabf3cf58f6f67d/xifimuwa.pdf
    • http://www.shipsupply.co.mz/wp-content/plugins/formcraft/file-upload/server/content/files/1608ae58361bc5---zefapimukese.pdf
    • https://www.erenang.com/wp-content/plugins/formcraft/file-upload/server/content/files/16083041724b48---resawowef.pdf
    • https://mmszke.hu/files/file/38280431450.pdf
    • https://www.brightfieldbusinesshub.co.uk/wp-content/plugins/super-forms/uploads/php/files/bo7t71q2clfblgc8p0obr7np5f/79947007252.pdf
    • http://mognational.com/wp-content/plugins/formcraft/file-upload/server/content/files/160804c989872f---rogatiwewizof.pdf
    • https://dsodrecital.com/wp-content/plugins/formcraft/file-upload/server/content/files/160740ac3c7612---92987003986.pdf
    • http://jointrilogy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608acc87376b9---jaxemap.pdf
    • http://forter.vn/hinhanh/file/numamizewatowibufipasipux.pdf
    • https://regalcabs.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160967fd84b5bb---14592977965.pdf
    • http://opalbiosciences.com/wp-content/plugins/formcraft/file-upload/server/content/files/160751ae4ba1d7---vufezazekubirek.pdf
    • https://laneopx.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608323d0d8ec7---18119037325.pdf
    • https://jjmassociates.com/wp-content/plugins/super-forms/uploads/php/files/06b5049418196df164caf1b48849d042/19714101039.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/Uplcv/~3/3CAf4wW3hvY/uplcv?utm_term=autocad+2014+with+keygen+free
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d899.bin
2e5b928e5e74068fa5214ccc71c059169051623dce9fefffe4b28cd4550b1496
pdf-font-stream PDF embedded font (sfnt) at offset 0xD899 5736 bytes
font_01_sfnt_off0000ec44.bin
76fddfac3dbc2c417d996d5fb029bb553d005b5ff9313af4a35a256a58ef5bf7
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC44 10596 bytes