Malicious PDF — malware analysis report

Static analysis result for SHA-256 659475971f78d61f…

MALICIOUS

PDF

80.4 KB Created: 2021-04-01 12:09:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 147a1a207cecd1af0826ffea069e913f SHA-1: 73476c1aa61edac918b2bff4dd66a2e52eebeb94 SHA-256: 659475971f78d61fc1d263cd3d96d0452ec13599d464998ce4e077968d427480
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also flagged this PDF with high confidence. The document body, though heavily obfuscated, contains text related to an annual report, suggesting a social engineering lure. No scripts were extracted, but the presence of external URIs indicates an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=yeovil+district+hospital+nhs+ft+annual+report
    • https://cdn.sqhk.co/wafasojudo/jjbchg0/food_giant_jackson_tennessee_south_highland.pdf
    • https://cdn.sqhk.co/sazurakuj/ojjxP2M/fonopavufi.pdf
    • https://kefuluseze.weebly.com/uploads/1/3/1/3/131398598/dolimolun_mumagazusili.pdf
    • http://help-bluebadgecustomer.com/13275800440puhpi.pdf
    • http://fullstacket.online/libros_de_lenguaje_corporal7p37n.pdf
    • https://cdn.sqhk.co/letarezetap/CsaOhdD/77800013952.pdf
    • http://kittyplay.online/john_deere_9500_combine_horsepowerhv1dp.pdf
    • https://meripowubizaj.weebly.com/uploads/1/3/5/9/135959363/1082940.pdf
    • http://shopyou.online/waxitopavutaxiravefo6i953.pdf
    • http://raicen.com/estados_financieros_definicionqxcap.pdf
    • https://cdn.sqhk.co/mexovaru/875QNj8/34418966580.pdf
    • https://lefexaro.weebly.com/uploads/1/3/5/3/135324439/70ef449.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/bolovopizonuki/8079385505.pdf
    • https://229c3593-bb94-4e5d-9b9f-ca3747df48ef.filesusr.com/ugd/145364_69f7f9e0a43646c7bb2fdb547e2c0661.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c118f0b5-25f6-4a27-b929-934a171ac74f/simcity_4_nam_mod_download.pdf
    • https://uploads.strikinglycdn.com/files/57afd07c-5487-479a-a9f5-8b64ff0f9465/top_notch_fundamentals_a_third_edition.pdf
    • https://uploads.strikinglycdn.com/files/359a15e9-ffaf-492c-8a68-b23c0ad69650/college_algebra_and_trigonometry_1st_edition_answers.pdf
    • https://s3.amazonaws.com/kizugokofo/how_do_u_factory_reset_a_kindle_fire.pdf
    • https://s3.amazonaws.com/viromibukoleliw/nesavixorapune.pdf
    • https://s3.amazonaws.com/kitakilesa/the_pact_2003.pdf
    • https://0502d5d0-a0f5-47b8-bc1c-644c46e4e431.filesusr.com/ugd/6cabbb_b034a3afe5b2418393ff690a6ea2a1a1.pdf?index=true
    • https://s3.amazonaws.com/xuvamuba/13908781914.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3ed.bin
1307bca34ad741f4af1b836591afb97ca0a3c2d593c19035d18ca12364dd6bd8
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3ED 5264 bytes
font_01_sfnt_off0000f5d8.bin
acf8fbf9b1a0348b8debfb5126a9c7c0313d0f5f8f3fc57d90f5c9dfa88c8342
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5D8 10384 bytes
font_02_sfnt_off00011973.bin
5521fb2d281bb72ad87610aa2ea7e11c06c1e73c286ad96dd0e486f54ccddf9f
pdf-font-stream PDF embedded font (sfnt) at offset 0x11973 16836 bytes