Malicious PDF — malware analysis report

Static analysis result for SHA-256 62c3a3e8abf0bad4…

MALICIOUS

PDF

82.9 KB Created: 2021-03-22 14:26:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 4c63dc06c8d4e97b129c1c4993b1cc7c SHA-1: b8e0f76b4c99510900fa7f721a154ec3ef73aa32 SHA-256: 62c3a3e8abf0bad48d3a0cc997ddc499df659761cb30b8d81d531876451722ac
144 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample was detected as a malicious PDF by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of a 'Payment redirection / bank-detail change lure' heuristic, combined with an external URI pointing to a download page, suggests the document is designed to trick users into downloading malware, potentially for financial fraud. No scripts were extracted, but the PDF structure itself is indicative of a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/123?utm_term=bulk+rename+wizard+pro+apk PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4487626/normal_602ac0841faa1.pdfIn PDF document text
    • https://cdn.sqhk.co/morureju/ig6Zha4/16201860377.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419415/normal_60435bbf9d126.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4496381/normal_6047c161016b3.pdfIn PDF document text
    • https://cdn.sqhk.co/tobamozusaj/jbigjcF/brazil_fifa_world_cup_qualifiers.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403818/normal_5fc72cda9eb57.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4392651/normal_5fcf65eb8e4c0.pdfIn PDF document text
    • https://cdn.sqhk.co/nisugavu/MhgOhhj/14454995445.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4387420/normal_604e300784bf5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4424647/normal_6041ee6cecd98.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4370317/normal_5fcfed1893245.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4416513/normal_60247d9d380a5.pdfIn PDF document text
    • https://cdn.sqhk.co/gunakawujo/giigiQt/pixel_grand_battle_3d_mod_apk_home.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4481819/normal_5fded8162ab35.pdfIn PDF document text
    • https://cdn.sqhk.co/nomitusibop/j6YpIrp/53004557338.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4427105/normal_5feffed3069dd.pdfIn PDF document text
    • https://cdn.sqhk.co/bepasasa/rHjh1CS/34311483168.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4503533/normal_6035b1a5773d4.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4419413/normal_5fc6d7e5add89.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • https://s3.amazonaws.com/zarevizebi/solving_linear_inequalities_in_two_variables_calculator.pdfIn PDF document text
    • https://s3.amazonaws.com/kuxegu/17782197987.pdfIn PDF document text
    • https://s3.amazonaws.com/lanorolowu/united_colors_benetton_baby_online_shop_usa.pdfIn PDF document text
    • https://s3.amazonaws.com/vovuzize/ti_bang_bang_vng_apk.pdfIn PDF document text
    • https://s3.amazonaws.com/mejobu/audi_a5_sportback_brochure.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4aa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE4AA 5180 bytes
SHA-256: bd86bc60066e8de74eb80980ed188a8d81643418c916fcc8e17e57157081bf70
font_01_sfnt_off0000f64d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF64D 4064 bytes
SHA-256: 79eef6a4c2b45af31d3c8b0cc71407642121cea73b101494b2800eb1dcbbc0ec
font_02_sfnt_off000102e8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x102E8 10948 bytes
SHA-256: fdb8d06e602ed25e2b5e74bc7e8c40a2eeaf92f644ac407265638f0fb7c98353
font_03_sfnt_off0001282e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1282E 16204 bytes
SHA-256: a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd