Malicious PDF — malware analysis report

Static analysis result for SHA-256 814b6f993db66e18…

MALICIOUS

PDF

183.3 KB Created: 2021-03-15 03:35:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f7ad0853d6cb81cee19face1b279011f SHA-1: 5606e20280571928aba2005488103ae1761e3507 SHA-256: 814b6f993db66e1825032127093363173132eb5c454c45bbbc94c98a0682af91
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded URLs that redirect to potentially malicious sites, masquerading as academic resources. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The presence of external URIs suggests an attempt to download further malicious content or redirect the user to a phishing page.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9987

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=horkheimer+critical+theory+pdf
    • http://xtina.online/book_review_examples_for_college_students90p3g.pdf
    • http://reduslim-italiaufficiale.site/wiloma9o2q.pdf
    • http://idealica-italiaofficial.site/luzakulisavidoodmzc.pdf
    • http://limaxinsto.xyz/baby_bjorn_carrier_original_manualq20p2.pdf
    • http://geleostone.online/248980656710mev6.pdf
    • http://ch-data-2a8fv9s.pw/49993814841vh5qa.pdf
    • http://jiropumewumavit.iblogger.org/perowujubewevufimumudemo.pdf
    • http://hq-cleartv.info/chapter_12_test_a_accounting_answer_keykem9g.pdf
    • http://studyweb.site/situvifjkv9.pdf
    • https://cdn-cms.f-static.net/uploads/4449996/normal_60224ad2a9ae7.pdf
    • https://cdn-cms.f-static.net/uploads/4459060/normal_603df67f856d3.pdf
    • http://femesugubu.iblogger.org/34430213469.pdf
    • http://oneplusonemain.xyz/fifty_shades_darker_movie_cast_mrs_robinsonla8wl.pdf
    • http://fineagencyy.com/funuxf9o00.pdf
    • http://datinge.site/robert_frost_poems_analysise486g.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://rapuwovire.rf.gd/how_long_to_roomba_batteries_last.pdf
    • http://sujetokotew.rf.gd/70907614225.pdf
    • http://birabigipo.epizy.com/30961193749.pdf
    • http://rakukofikojoku.epizy.com/mijit.pdf
    • http://tuzoxizusuzu.epizy.com/can_you_make_bread_in_a_bread_machine_with_regular_flour.pdf
    • http://gigigij.rf.gd/juzujatabegi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00028b1e.bin
9114db9ae3d22009c88d01a217220d1a843920a96b2867a8f04fd21ca661c46f
pdf-font-stream PDF embedded font (sfnt) at offset 0x28B1E 5028 bytes
font_01_sfnt_off00029c3a.bin
867104a7ede910a7d742b40f7f26aa7a16c7e8b799fb64cf9efa9b92fd80aa24
pdf-font-stream PDF embedded font (sfnt) at offset 0x29C3A 10980 bytes
font_02_sfnt_off0002c10b.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x2C10B 4324 bytes