Malicious PDF — malware analysis report

Static analysis result for SHA-256 71564a392b901a47…

MALICIOUS

PDF

82.8 KB Created: 2021-03-15 00:13:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b1c79e7a9abe828d10ad440d66b051d9 SHA-1: 9bfeb4035992ec5b84774c6b91edbc3ff936e2cb SHA-256: 71564a392b901a47e4d495ac2f1c2fe7d5c3eac614aa1e7016f77a06faa86b77
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were directly extracted, the PDF structure and embedded URI suggest it's designed to trick users into clicking a link that leads to a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=ammonia+absorption+refrigeration+system+pdf
    • https://gorejirulikem.weebly.com/uploads/1/3/4/7/134738880/lemako.pdf
    • http://tasagojolexi.iblogger.org/is_sky_map_app_free.pdf
    • https://xatefokagakutil.weebly.com/uploads/1/3/4/1/134108848/mefas.pdf
    • http://lovumodezubudem.iblogger.org/91860555604.pdf
    • http://vebumugaw.22web.org/woxotaduwikawe.pdf
    • https://wuxorazaw.weebly.com/uploads/1/3/2/7/132712222/delotodirexaler-wipiru-tutuvelitizowem.pdf
    • https://vojidejera.weebly.com/uploads/1/3/2/6/132695434/6986326.pdf
    • http://rutonujak.iblogger.org/84873414182.pdf
    • https://nirereki.weebly.com/uploads/1/3/1/4/131483126/lovomedokevufa-nerowaxewefazoj-zunutaz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://kibululugavi.epizy.com/22965493626.pdf
    • http://mejefelutirarej.epizy.com/59438604173.pdf
    • https://s3.amazonaws.com/fumiposamisur/dezixodakeluriva.pdf
    • http://zuluduk.epizy.com/exploratory_spatial_data_analysis.pdf
    • http://nopatiget.epizy.com/ruxote.pdf
    • https://s3.amazonaws.com/jipowumat/what_is_rawls_justice_as_fairness.pdf
    • http://sebubexegan.rf.gd/sipajodejujemifenewim.pdf
    • http://litopuputorer.rf.gd/arbys_cheap_menu.pdf
    • https://s3.amazonaws.com/fulosobezur/dagewabisane.pdf
    • http://lutubipejor.rf.gd/kezumozatidotapoziletax.pdf
    • http://tovigubiv.rf.gd/dupusawewa.pdf
    • http://gufidom.rf.gd/numakugebaruvewiwadekuvi.pdf
    • https://s3.amazonaws.com/tisegovofu/zodawesunudisorijusibunej.pdf
    • http://voxotili.epizy.com/linear_equations_practice_sheet_b_answers.pdf
    • https://s3.amazonaws.com/lurutopobi/manualidades_para_nios_sobre_otoo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000100ec.bin
4b547ec03a82c6ec1b4da5920797a8b32a40ab504851a4cb456917f324398703
pdf-font-stream PDF embedded font (sfnt) at offset 0x100EC 5560 bytes
font_01_sfnt_off000113be.bin
597bd9f91b60fbf4652ad640eb6b54c026b4f7151a29922ae59017fddc4c4c56
pdf-font-stream PDF embedded font (sfnt) at offset 0x113BE 12692 bytes