Malicious PDF — malware analysis report

Static analysis result for SHA-256 709553acccde0af1…

MALICIOUS

PDF

80.8 KB Created: 2021-03-20 08:35:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 88f9933ed4cace1447ca38393695fa83 SHA-1: 7980e352aa2e1e2bfecb54ab1b84607ff237b68c SHA-256: 709553acccde0af19e7ac197359ec273c3d4ee6b539938497b6909351ace05c6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, identified as a phishing lure. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URL likely leads to a phishing page or a further stage of malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=contaminacion+del+aire+pdf+unam
    • http://timinome.getenjoyment.net/percy_jackson_the_lightning_thief_book_chapter_14.pdf
    • http://dosijefa.mypressonline.com/how_do_i_reset_my_dometic_3_button_thermostat.pdf
    • https://cdn-cms.f-static.net/uploads/4417659/normal_600eaf11647cc.pdf
    • http://xuzobinemipivor.mygamesonline.org/80255714442.pdf
    • http://tinesemexogo.mygamesonline.org/how_did_the_civil_war_and_reconstruction_change_america.pdf
    • http://pirojibanenuzi.getenjoyment.net/8217669922.pdf
    • https://cdn-cms.f-static.net/uploads/4485149/normal_601a82288aa8f.pdf
    • https://cdn-cms.f-static.net/uploads/4370288/normal_6021a3dc28499.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/b9358c00-8c8f-4a98-a705-4460f96871ad/jusofes.pdf
    • http://fezibebub.rf.gd/57612781876.pdf
    • https://s3.amazonaws.com/wolawatin/amazon_operations_manager_salary_indianapolis.pdf
    • https://uploads.strikinglycdn.com/files/ae145368-0aca-4ccb-91c6-719ddaa20ca2/sonic_sausage_breakfast_burrito_nutrition_info.pdf
    • https://s3.amazonaws.com/zafirawit/mla_works_cited_file.pdf
    • http://kipejefanowisu.atwebpages.com/93575125996.pdf
    • http://dowuvoduwitovos.atwebpages.com/face_benjamin_zephaniah_download.pdf
    • http://zapesezowu.rf.gd/nostalgia_4_quart_ice_cream_maker_reviews.pdf
    • https://uploads.strikinglycdn.com/files/4e353d06-7973-487a-ad14-b4bcb4a25e4c/james_and_the_giant_peach_summary_chapter_2.pdf
    • https://s3.amazonaws.com/legapatatezisa/how_to_draw_better_lines.pdf
    • https://uploads.strikinglycdn.com/files/f10cf728-98dd-4b95-bbe3-80332a55b5c7/hobart_mixer_parts_diagram.pdf
    • https://s3.amazonaws.com/kigavanus/50683978982.pdf
    • http://sovizaz.epizy.com/mysql_coalesce_vs_isnull_performance.pdf
    • https://s3.amazonaws.com/gozilum/what_is_in_dunkin_donuts_blueberry_coffee.pdf
    • http://jeloneliva.epizy.com/pdf_to_word_converter_free_online_nitro.pdf
    • http://juludiripo.myartsonline.com/digewik.pdf
    • https://uploads.strikinglycdn.com/files/4088309a-64f4-44fd-b472-1e0b3e3ecff7/what_is_the_best_app_for_drawing_on_pc.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fce1.bin
b99974d136919d75de6db9fb26d0a9d2c625f7823c7dfd408f321690ae52a218
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCE1 5028 bytes
font_01_sfnt_off00010de2.bin
0d11a1657274a77557698fce969bdfd484176625e020fafd33434b060041ee63
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DE2 11684 bytes