Malicious PDF — malware analysis report

Static analysis result for SHA-256 8230432d79bcf857…

MALICIOUS

PDF

81.4 KB Created: 2021-03-25 10:23:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: d9c469f5c06305ace90b21665e1bdb11 SHA-1: 55fb6ab1517e38ba13d9314b22aecac02e775ea5 SHA-256: 8230432d79bcf85700aa20223108b3fbf7f356836820ce82a2313615a2b9b3da
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/123?utm_term=antivirus+freeware++full+version PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4469103/normal_5fd70f1910bb1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4413347/normal_6001e3ebbe8c4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4494436/normal_6025a92b44300.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375708/normal_600bf0a026da4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447912/normal_602532a670423.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386363/normal_601f3a07d66ed.pdfIn PDF document text
    • http://roflan.site/zombie_shooting_game_for_pcw10ut.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419452/normal_5fda8ae2c6b62.pdfIn PDF document text
    • http://sokfresh.fun/botofunetemoguditutvxrz.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/wajufifenoxuj/which_university_is_best_for_data_science.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1c8e65db-f3c8-4d93-a9ff-d4d7c7329437/93762746760.pdfIn PDF document text
    • https://s3.amazonaws.com/gazivemon/669798273.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/832b0d26-5278-4acd-b8d8-6f7f1e50562c/19453909390.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/81f1743b-5680-4595-a02a-33c907d4f001/12294281705.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a28eb2f-2429-49c3-a29a-88cb5176eae9/lurubazimusumuduzisugaxak.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e65c808c-d37a-4790-9111-0569d07b2b67/waltham_park_new_testament_church_of_god_kingston_jamaica.pdfIn PDF document text
    • https://s3.amazonaws.com/nemafu/84867348764.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4580a9ab-b1c8-4a0d-9447-86d999ef8d90/nesunulaxovikewabejuxo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bb6e4bd3-6c53-4510-bade-09be09ffa5d6/que_es_educacion_superior.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/165a117f-760f-47fc-8f20-0a8de94ccf06/can_scoliosis_cause_hip_impingement.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8c7f5ccd-5790-4cab-a029-351b0ddafa53/nigosuzenoraraxowofariwov.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/85e478d5-592b-4c04-9d33-22351270117e/lujudebovarikasewobijogi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001021a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1021A 4900 bytes
SHA-256: 7279d58f033fb792404ac4f43ef13c5467ff0ad0179fe53a7aef9e503147a1b5
font_01_sfnt_off000112e9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x112E9 10960 bytes
SHA-256: 7855010c6834d4303300e0f1d1ede8b9f9bab8f3bfd7a333cea9d806ef574b97