Malicious PDF — malware analysis report

Static analysis result for SHA-256 78f293094e2c61a6…

MALICIOUS

PDF

78.7 KB Created: 2021-03-13 13:10:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aba657ce4b3804bd4820b44bdb5637c8 SHA-1: ee50c19c28baa02735526f92b4a686bc8fa9fdcf SHA-256: 78f293094e2c61a6123501711b6dd73512f5a7bbf3b2a9e9972f257eefba7687
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, with a high risk score. It contains an embedded URI pointing to a suspicious domain, likely intended for phishing or malware distribution. Although no scripts were explicitly extracted, the presence of embedded URIs and the nature of the heuristics suggest an attempt to redirect the user to a malicious site, potentially leveraging PDF vulnerabilities or social engineering.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=medical+term+meaning+pertaining+to+under+the+skin
    • http://getliterate.online/semufutijogeponuxegelitim907v2.pdf
    • http://allerop.xyz/bharat_gas_connection_reactivation_formihqdh.pdf
    • https://pujuwofox.weebly.com/uploads/1/3/4/8/134882524/gonul_minas_xutibaliwog_gababelipok.pdf
    • http://vadememejunozax.iblogger.org/world_continents_outline_map.pdf
    • http://zuluwana.iblogger.org/88363894806.pdf
    • http://leoidet.xyz/dragon_quest_builders_2_switch_salecudf8.pdf
    • http://kovokowem.iblogger.org/culver_s_application.pdf
    • https://marexuja.weebly.com/uploads/1/3/6/0/136056735/4629876.pdf
    • https://gojatoxemoniro.weebly.com/uploads/1/3/4/8/134894745/sisufusaruv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://tipakofixu.epizy.com/past_simple_past_continuous_exercises_intermediate.pdf
    • http://botevurisupom.rf.gd/14386128242.pdf
    • https://92ddf5cc-4ce7-4caf-b117-8241c553a727.filesusr.com/ugd/42bae0_50ee61cd00514a458781f2872f1e71d9.pdf?index=true
    • http://talamilikobapi.epizy.com/gelalafupubaven.pdf
    • http://tilixufevoj.epizy.com/fewosowuvejepuzawagota.pdf
    • http://zofutigo.epizy.com/arere_ekkada_female_song_naa_songs.pdf
    • http://pefafimu.rf.gd/vukuxozimepadasidevaja.pdf
    • https://21a67f6d-2aea-439f-a910-ed4feb6be009.filesusr.com/ugd/173616_c9e1754f40aa449084c193076b3b1e4e.pdf?index=true
    • https://7095e710-59ac-4d27-8a5a-f3bbcaf65deb.filesusr.com/ugd/418e76_e205db9dd9f3441a80a3e78d8d9d072a.pdf?index=true
    • https://5926284e-b61c-4ed0-95e5-27b9feedd2c3.filesusr.com/ugd/50c35f_a3cf96b68a5c43fd8f231ad1f5bb7d79.pdf?index=true
    • http://goguvero.epizy.com/gate_2018_answer_key_mathematics.pdf
    • http://nadadeze.epizy.com/lubijujob.pdf
    • http://zutagokakaki.rf.gd/15652441930.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5cb.bin
cebd2bfa12ab5f6e10ca46d859c5da0643a4c5ac23404a8751ccb31e5262bc0b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5CB 5556 bytes
font_01_sfnt_off0001088e.bin
38556cd954546f4d851bec8bf68381877e3833902af948fe36ccfaa18e8bbda6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1088E 10844 bytes