Malicious PDF — malware analysis report

Static analysis result for SHA-256 6d7a7ae68fc9d52e…

MALICIOUS

PDF

71.0 KB Created: 2021-03-27 17:39:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 22cb0ed4a4b340d32fcd27ab3497b40e SHA-1: 529a5f39a432361f3eb9c32d0cb80a1ec0be30a7 SHA-256: 6d7a7ae68fc9d52e268ad48af2cecc176ad996332ab098dde3b09bea2dad4aca
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. The embedded URL suggests a lure to download a manual, which is a common phishing tactic. Although no scripts were explicitly extracted, the PDF structure and the nature of the detection indicate it's designed to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=everstart+maxx+sl097+manual
    • https://cdn-cms.f-static.net/uploads/4420599/normal_60265b42d2755.pdf
    • https://cdn.sqhk.co/letarezetap/hbibhgc/87528995614.pdf
    • https://cdn.sqhk.co/wisaputal/gw3hcii/tozix.pdf
    • http://center-about.com/bharat_full_movie_filmywapvus0u.pdf
    • http://nutosuvitiraj.scienceontheweb.net/bakibexelilakogog.pdf
    • http://narixuz.mypressonline.com/62992710455.pdf
    • http://it50disconto.info/que_es_un_bucle_anidado_en_programacionmj7ii.pdf
    • https://cdn.sqhk.co/bamopilu/Wieh8ha/amazon_gutschein_fur_kindle_einlosen.pdf
    • http://usacreditcheck.info/dance_academy_full_movie_freeqaioc.pdf
    • http://norudumof.22web.org/64047658236.pdf
    • https://static.s123-cdn-static.com/uploads/4446646/normal_5fe16d3fe4dde.pdf
    • http://bovibuvebus.getenjoyment.net/sanepegeweb.pdf
    • http://mjawebdesign.net/netgear_n600_wifi_cable_modem_router_instructionszwuca.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/b61ae921-d093-4030-943e-7cbe1b556097/57946816461.pdf
    • https://uploads.strikinglycdn.com/files/125cfc2d-dccf-45b7-b5f7-a2409e6cc184/gobozoxenowunokuzuba.pdf
    • http://dinoxisajuz.rf.gd/a4_half_fold_brochure_template_word.pdf
    • https://uploads.strikinglycdn.com/files/6f4342f7-e4c5-4747-8b37-dc4180ef7088/john_calvin_institutes_of_the_christian_religion_translated_by_henry_beveridge.pdf
    • https://uploads.strikinglycdn.com/files/c0fa8910-cac0-45ad-acd3-1e1d3dd5cfb7/mogugonimusiworovobese.pdf
    • https://uploads.strikinglycdn.com/files/92d62b41-48b8-4ede-89b2-7f3c50f2f428/big_fish_audio_vintage_guitar_loops.pdf
    • http://nosawakudik.myartsonline.com/dekitavu.pdf
    • http://sozufig.rf.gd/98428514256.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d7f9.bin
b905f340f75fddc547608125bbb92eefe3fa05083fd6512b31f8cc8ab9d02719
pdf-font-stream PDF embedded font (sfnt) at offset 0xD7F9 5296 bytes
font_01_sfnt_off0000e9ec.bin
85ea912da833bc8131d5c05613a396ae7fe103ed96e935bcd78c9a1ca4102256
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9EC 10856 bytes