Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f262713809c5daa…

MALICIOUS

PDF

135.2 KB Created: 2021-03-20 07:19:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 03d02f3c86dbf9d6c947883fb20fdac8 SHA-1: 52da06e0748e3794464ed011f6ed2eb2dba8297f SHA-256: 7f262713809c5daa1c13c5a6107ed45b85e716f53c2cf3304a978fb8e6b788e1
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by a machine learning classifier and ClamAV. It contains language suggestive of an invoice or payment lure, and embeds a URL that likely leads to a malicious payload. While no scripts were directly extracted, the PDF structure and embedded URI indicate a phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/123?utm_term=amadeus+reissue+commands+pdf
    • https://benokonafininu.weebly.com/uploads/1/3/4/6/134606635/3411404.pdf
    • https://static.s123-cdn-static.com/uploads/4449605/normal_5fffb62929f59.pdf
    • http://jiludedo.iblogger.org/94038678602.pdf
    • http://fuxejezosajusop.22web.org/organizational_structure_template_online.pdf
    • https://cdn-cms.f-static.net/uploads/4455183/normal_604ca28aa3a13.pdf
    • https://goguribepolim.weebly.com/uploads/1/3/0/7/130739596/17cb9ee065e2b05.pdf
    • https://cdn-cms.f-static.net/uploads/4480149/normal_6019a40f31421.pdf
    • https://cdn-cms.f-static.net/uploads/4481278/normal_6021a564f28d9.pdf
    • http://newuwedeza.mypressonline.com/bedtime_stories_read_along.pdf
    • https://static.s123-cdn-static.com/uploads/4453914/normal_5ff7e12574b0e.pdf
    • https://geguxawuxereko.weebly.com/uploads/1/3/1/3/131379712/doxubi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://ab60d57a-1f92-408f-9079-0b325776b613.filesusr.com/ugd/724fb5_07856c41f21e43bfae5a8e7aa36636a4.pdf?index=true
    • https://s3.amazonaws.com/bisazabe/voxij.pdf
    • https://26f2e344-8444-46ea-90c9-5a893bcc2fb3.filesusr.com/ugd/b8c837_ebabae8d79f14830a9949fcca09e8598.pdf?index=true
    • https://s3.amazonaws.com/lanorolowu/vizolenewedeja.pdf
    • https://s3.amazonaws.com/bupaxomu/78278650683.pdf
    • http://kikanelomer.onlinewebshop.net/20122923882.pdf
    • http://gumigojozupe.epizy.com/georgia_power_bill_template.pdf
    • http://lamuverifob.epizy.com/siwukoxalujodofopogugoz.pdf
    • https://s3.amazonaws.com/selivuvumepaveb/fz_bike_200_cc_price.pdf
    • https://25f35837-e8ad-4357-b490-8f69bec4165a.filesusr.com/ugd/96c61c_ad20bcda9d2e4cca956361cfcf2f4b8e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001ca25.bin
440fab83cc750dc954eef927fa1159f498d5ef06a455bd716ebcaf55c9793bd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CA25 5060 bytes
font_01_sfnt_off0001db2e.bin
6fb02298af4ace3d305a42fb98ecf144db66fade51d854cf90390964a8ab7dfd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DB2E 11092 bytes
font_02_sfnt_off00020100.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x20100 4324 bytes