Malicious PDF — malware analysis report

Static analysis result for SHA-256 7eac46c78ec11865…

MALICIOUS

PDF

76.6 KB Created: 2021-04-07 11:09:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 57b59e91dba1a8fc1ba3196bb06740ec SHA-1: 7bbab2aa9639a3ba29bfbdba3be9093e7ebf8fc5 SHA-256: 7eac46c78ec11865ebf9af310b25d8d8a84ae7fcf516337b794f660c1f274d7c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains multiple embedded URLs, with one specifically referencing 'atvio smart tv 50 manual', suggesting a lure to a phishing or malware distribution site. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the presence of external URIs and the overall detection profile point towards a phishing or downloader attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=atvio+smart+tv+50+manual
    • https://cdn.sqhk.co/jirudumom/Ethheii/gikumilopatipez.pdf
    • https://cdn.sqhk.co/tojorovexuw/JQiXqih/86596685924.pdf
    • http://espacecmb.xyz/249014675335tjh.pdf
    • https://cdn.sqhk.co/fivufotimad/SJH8ihO/sadixazamezawaveluzivinum.pdf
    • https://static.s123-cdn-static.com/uploads/4371783/normal_5fe32dd77eb25.pdf
    • https://static.s123-cdn-static.com/uploads/4453103/normal_5fee33ef1b0f2.pdf
    • https://static.s123-cdn-static.com/uploads/4482418/normal_600171d3d7317.pdf
    • http://blablablacar.online/kenshi_slavery_mod9365b.pdf
    • https://cdn.sqhk.co/bafujifi/NrjcjiL/angie_s_list_categories.pdf
    • http://fevalugumaj.22web.org/the_bible_timeline_chart.pdf
    • https://static.s123-cdn-static.com/uploads/4449000/normal_5fcd66127ac01.pdf
    • http://tinonijo.iblogger.org/medical_report_translation_service_singapore.pdf
    • https://cdn-cms.f-static.net/uploads/4459629/normal_603405d58323e.pdf
    • http://help-service-support.com/253690002151ysbx.pdf
    • http://telewapor.22web.org/40923952724.pdf
    • https://cdn.sqhk.co/pinofizulag/jeiaBhd/defolokowajixeratapukitiz.pdf
    • http://warewakeb.sportsontheweb.net/1573801203.pdf
    • http://max-lifting.store/hp_elitebook_2560p_launch_date63c0s.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://bufijonewufo.onlinewebshop.net/ahle_hadees_namaz_ka_tarika.pdf
    • http://mifojizu.myartsonline.com/vomeresexu.pdf
    • http://sexililelaweru.rf.gd/el_bogotazo_memorias_del_olvido.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef92.bin
73987df8d0c57df0020ba4b2085c4dd680a750cff57e1188983737c3b8583300
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF92 5148 bytes
font_01_sfnt_off000100fa.bin
b602f97a656bdde467136acbd69ec85980968fb619ce49fbe344bd399c5ed775
pdf-font-stream PDF embedded font (sfnt) at offset 0x100FA 10488 bytes