Malicious PDF — malware analysis report

Static analysis result for SHA-256 76bd86eed0de445a…

MALICIOUS

PDF

69.4 KB Created: 2021-04-07 09:51:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 570d9e2650b68f830ce525b0414a7ad4 SHA-1: b8a9a880422d11708888ec124f39ac7c9268e894 SHA-256: 76bd86eed0de445a9931456ee3b7b40581bc1ce556b48a2a5fefa2055de002fc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with multiple heuristics indicating the presence of external URIs and embedded URLs. The document body, though heavily obfuscated, contains text related to creating PDF download links, suggesting a phishing or malware distribution lure. The embedded URLs likely serve as the mechanism for delivering the malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=create+download+link+for+pdf
    • https://bisadujepuza.weebly.com/uploads/1/3/4/4/134444209/1e82d9086.pdf
    • http://verifiedbadges-form.com/bejofamolisanugevaxaj9wosu.pdf
    • http://giftcard-sale.store/4liker_latest_versionp5fhl.pdf
    • http://in-step.shop/kerala_university_msc_zoology_syllabus87rlb.pdf
    • http://amsidgi.xyz/kenmore_washing_machine_tech_support1qfmh.pdf
    • https://sepuvomaxobaba.weebly.com/uploads/1/3/5/3/135311468/xudasopexiwuvu.pdf
    • http://yoganchik.space/compassion_focused_therapy_worksheetsnumxy.pdf
    • https://volilisaxox.weebly.com/uploads/1/3/1/4/131453747/3390971.pdf
    • https://zisirusezudi.weebly.com/uploads/1/3/4/8/134846547/wusawutiwopujudogej.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/d60aa5ac-6315-4212-8bfc-98f359435b03/96150491786.pdf
    • http://kabekexivebinef.epizy.com/data_structures_in_java_examples.pdf
    • https://s3.amazonaws.com/xefezesebusu/psd_to_html_email_templates_free.pdf
    • https://s3.amazonaws.com/pegozegi/lenaroxuxogazafo.pdf
    • https://680e7e7f-99bb-4309-8a01-ecc910dc7690.filesusr.com/ugd/717a42_f446cdd096c349cf9df64d7d92ba5597.pdf?index=true
    • https://e97408dc-4b05-4e3b-9f19-f4127feb49ef.filesusr.com/ugd/a42eed_a005335017ab462e9cdd1bffc2b477a2.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a21f101a-7c69-4f29-8a3f-5a597ee95ebd/suzedupeneramutoxawemo.pdf
    • http://mivuzovi.epizy.com/green_smoothie_challenge_recipes.pdf
    • http://furamexexi.rf.gd/rupobobifosufarugibusak.pdf
    • https://s3.amazonaws.com/memexelu/52333880864.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d3c0.bin
8f6e1a712b6ee39b6e69bc4402d922b708df937ffebbdc1bd522e4fc03181527
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3C0 4916 bytes
font_01_sfnt_off0000e49f.bin
493e66f849a850b7f25346b1b8d791f8f33740af77edf15106856276f651697d
pdf-font-stream PDF embedded font (sfnt) at offset 0xE49F 10480 bytes