Malicious PDF — malware analysis report

Static analysis result for SHA-256 80c01d01288cd764…

MALICIOUS

PDF

85.7 KB Created: 2021-03-13 14:46:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fc45402d71e6377078f34b1410b486a5 SHA-1: a92f32044dd607f9142c24a68fd50b8c65b6cf46 SHA-256: 80c01d01288cd7649c977339099b249c8f778c88b4192505a67e1e58eafb5457
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, identified by ClamAV as 'Pdf.Phishing.Trojan'. The ML classifier also flagged this PDF with high confidence. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, and the embedded URI is the primary indicator of malicious intent, likely leading to a phishing or malware download site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/award?keyword=english+descriptive+writing+pdf
    • https://cdn-cms.f-static.net/uploads/4370996/normal_600c8ca3ecf0a.pdf
    • https://static.s123-cdn-static.com/uploads/4401703/normal_5ff71c092b1af.pdf
    • http://mowisadewojapu.22web.org/komororepesudulafidag.pdf
    • https://cdn.sqhk.co/tategupet/cfSYd9h/geregivabo.pdf
    • https://static.s123-cdn-static.com/uploads/4367268/normal_5ff481858aa6d.pdf
    • https://cdn.sqhk.co/torazanopuni/hclhbh3/werewolf_hd_wallpaper_for_android.pdf
    • https://suvadigefutom.weebly.com/uploads/1/3/1/4/131406455/9272121.pdf
    • https://static.s123-cdn-static.com/uploads/4476429/normal_6002ae4a29127.pdf
    • https://cdn.sqhk.co/kixobaza/Wmhhih1/71021925612.pdf
    • https://vifewilepame.weebly.com/uploads/1/3/4/0/134012930/wazotegawar_relopupixiduj_gajirul.pdf
    • http://rotixumuzu.22web.org/how_to_reset_sentry_safe_if_forgot_combination.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://titarejidawe.epizy.com/zezeberu.pdf
    • https://s3.amazonaws.com/xixonu/autoit_script_tutorial.pdf
    • http://tokaverojov.epizy.com/9th_tamil_guide_free_2018.pdf
    • https://s3.amazonaws.com/wutisigila/what_is_a_social_contract_in_government.pdf
    • https://8b2103c5-345b-48fd-98e3-f19c90c4efd0.filesusr.com/ugd/0e2875_59994300bdab4f7f8c4b72b242f14e9d.pdf?index=true
    • https://s3.amazonaws.com/mukut/17838821687.pdf
    • https://bb491b24-4c81-4ccc-8daa-bf1baeb171c2.filesusr.com/ugd/93c935_b8e6430f193a4c2c81012d39157dd392.pdf?index=true
    • http://mimelaketikapex.rf.gd/27319679340.pdf
    • https://s3.amazonaws.com/sedowedi/latafevabakivol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010597.bin
4c4998e0fcc86da24e0db8b41c6d679c8d507f06c78ba5608f63115657a3d036
pdf-font-stream PDF embedded font (sfnt) at offset 0x10597 4996 bytes
font_01_sfnt_off0001169f.bin
0ca408c75e03cc48ff2d2460175e4b5ad87e1a6a6629e0c719ad9d7131718a1a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1169F 10828 bytes
font_02_sfnt_off00013b87.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x13B87 4324 bytes