Malicious PDF — malware analysis report

Static analysis result for SHA-256 809584a515b95c8c…

MALICIOUS

PDF

82.1 KB Created: 2021-04-03 07:22:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c7e76781551c8ee479fa947abe2e6c4c SHA-1: 435e31c859c205da291d8f7ade34564af1da604c SHA-256: 809584a515b95c8c1339dee66caa2229e9f2d0b2e7c97af576f8b58512913863
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the presence of an external URI within the document body suggests an attempt to redirect the user to a malicious site, potentially for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=babies+r+us+banister+baby+gate
    • http://cccckkkkkdd.space/bridget_jones_diary_2_full_movie80af0.pdf
    • http://about-central.com/75313527200lulb7.pdf
    • http://gaydating.world/what_is_a_good_beginner_fly_fishing_setupoin1y.pdf
    • http://zoomita.space/english_101_montgomery_collegeet19h.pdf
    • http://fullcreditreport.info/bigoputorasukizxc.pdf
    • http://mynasert.online/23341191032ostwp.pdf
    • http://tunumurelumuget.iblogger.org/97824704594.pdf
    • http://helplnstagram-confirm.com/why_wont_my_new_dell_computer_turn_on569vd.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/eddeaf8a-757c-4a94-8390-79cd9c32b886/mefem.pdf
    • https://s3.amazonaws.com/zakunafu/71423065250.pdf
    • https://s3.amazonaws.com/tupofelasujewas/22229154041.pdf
    • https://s3.amazonaws.com/lanaladu/71971821658.pdf
    • https://uploads.strikinglycdn.com/files/9dffb3d5-7e9f-4872-a680-3066b760c2b5/lisafamisumibolefevudurew.pdf
    • http://magakawigola.epizy.com/gajujewagig.pdf
    • https://s3.amazonaws.com/radubozufiwo/what_true_love_really_is_quotes.pdf
    • https://s3.amazonaws.com/fatikonavori/27785829414.pdf
    • http://zexizel.epizy.com/harry_potter_wands_list_universal.pdf
    • https://s3.amazonaws.com/zeworibuzoza/the_theater_experience_rcc_version-13th_edition_by_edwin_wilson.pdf
    • https://s3.amazonaws.com/tizowodifi/canadian_solar_warranty_sheet.pdf
    • https://uploads.strikinglycdn.com/files/6bc5e83d-0ec6-4a74-a294-33828da5899e/how_to_fix_leaky_humidifier.pdf
    • https://uploads.strikinglycdn.com/files/fcfdb1ec-3dc3-4e7e-a3c3-12326b17eab3/taco_bell_new_items_october_2020.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010478.bin
37224358204eff86ef7ab1d9d5ec502e077dc606d198aa62c5d7c57a8f06b5f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x10478 5112 bytes
font_01_sfnt_off000115f5.bin
1889b03c2afddbdee0c4c41ecd776393eee83d4bc92a635b42c08ae5702b4d88
pdf-font-stream PDF embedded font (sfnt) at offset 0x115F5 10504 bytes