Malicious PDF — malware analysis report

Static analysis result for SHA-256 6eeceb4cd2877aa0…

MALICIOUS

PDF

85.7 KB Created: 2021-03-16 03:28:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8db7c1710bcea848f809d78a9dfcbdee SHA-1: 167db1ac7d0ae1466f6a197800d718ac710dedea SHA-256: 6eeceb4cd2877aa021a37a5119f7dfa9db85a36308db2039ab61e323930a50a7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains embedded URLs that likely lead to further malicious content or phishing pages. The document body is heavily obfuscated, but the presence of external URIs suggests a phishing or content-luring attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=jeevan+umang+brochure+pdf
    • http://zuzimosutikume.22web.org/95103443165.pdf
    • https://cdn.sqhk.co/wafudovop/iNjeijZ/distance_calculator_meters_to_feet.pdf
    • http://avit0.cc/rivasibikuduby5yvz.pdf
    • http://50offstore.info/nubaxapebirasemebpdlyu.pdf
    • http://obzorov.site/c_reference_guide80gzr.pdf
    • http://floradoma.net/42611204764i44ic.pdf
    • http://montana-media.com/g_shock_ga_1100_manualx4c2e.pdf
    • https://cdn.sqhk.co/tosuwukiwate/jawjbhi/2998737619.pdf
    • http://carbags.site/78806360937ekaba.pdf
    • http://inglassrus.ru/danby_window_air_conditioner_12000_btu_reviewucc6l.pdf
    • https://cdn.sqhk.co/gilevetu/f7Q2RBa/homes_for_sale_sunset_views_st_charles_il.pdf
    • http://znalomstvavip.site/3274438807m9vl0.pdf
    • https://cdn.sqhk.co/tavevalurov/eQemDw6/mejojefi.pdf
    • http://samefinudamolu.iblogger.org/livro_calculos_trabalhistas_2020.pdf
    • http://samo-katim.ru/15488144815mpsnc.pdf
    • http://itsamorem.com/ravarakunaje04.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://xonowazibekaz.epizy.com/argumentative_essay_writing_worksheets.pdf
    • https://uploads.strikinglycdn.com/files/4cf8129d-7220-43e2-9e31-c485b8d4895c/50905566844.pdf
    • http://golofupatawef.epizy.com/facebook_recovery_page_not_working.pdf
    • https://uploads.strikinglycdn.com/files/86d97490-8a9c-402e-9ee5-f9cbbe6376f7/basic_physics_a_self-teaching_guide.pdf
    • https://uploads.strikinglycdn.com/files/3d21bb5b-212c-400e-b2a9-0e7a7a181df8/what_is_the_healthiest_at_taco_bell.pdf
    • http://vokozebutiri.rf.gd/asientos_contables_ejemplos_resueltos_peru.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fba1.bin
41e0f6abfe702c068d3ae008f6eefb0efceb1918447d23597e9530de2ed74230
pdf-font-stream PDF embedded font (sfnt) at offset 0xFBA1 5548 bytes
font_01_sfnt_off00010e5b.bin
9ecc3416700f83f93f59cacc6f043227e234957cb50529f6153feeed141a8109
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E5B 11012 bytes
font_02_sfnt_off0001342b.bin
4a3d97cb0f01b67db0f2c0c67b38c82a67e4beafd846d3a18a1ca53b20acedf2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1342B 16100 bytes