Malicious PDF — malware analysis report

Static analysis result for SHA-256 834644d15367bb81…

MALICIOUS

PDF

709.5 KB Created: 2020-12-20 07:57:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-16
MD5: eaadf06b63c0339fd808ac885852d55c SHA-1: e04271cc6c2557b1ac8a6654d5117a1967cac81e SHA-256: 834644d15367bb815a17ac3318d12945a045e36e1f624ff243fdef3de3ac0a87
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains embedded URLs, one of which is flagged as suspicious. The heuristic 'SE_INVOICE_LURE' suggests the document's content is designed to trick the user into taking action, such as clicking the malicious link. ClamAV detection further confirms its malicious nature, identifying it as 'Pdf.Phishing.Trojan'. No scripts were extracted, but the presence of a suspicious URL and the lure heuristic strongly indicate a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7253

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffking.ru/aws?utm_term=hutchison+telecom+annual+report PDF link annotation
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/7a3caf30-eb8f-47ad-b861-cd0e410bccac/minasolevurapisapepawiz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/19f71c73-9992-4173-ad9e-c5140fac3da3/turovuxaxoposuza.pdfIn PDF document text
    • https://s3.amazonaws.com/wajufifenoxuj/89374245207.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc69cd5bda9c57a97e5d88e/t/5fce6b77d336b863f0f7dae6/1607363447563/oldest_golden_boot_winners_premier_league.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc30fa5bda9c57a97cc46e9/t/5fc59d8e3c02f22b9dcdc8cb/1606786447711/ff14_crafting_leveling_guide_70-80.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc573685bcb0228a2a13196/t/5fcbf38d9aa2de0c647c3dce/1607201677880/1285473763.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/654022bc-9c54-4672-943f-665beed701e7/gibbed_weapon_codes.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fdcba3646033b444b395ad1/t/5fdcbef93f4cde091ae26140/1608302330020/31375264704.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5077e6d49a06bb8876c0/1606373497694/tilalame.pdfIn PDF document text
    • https://s3.amazonaws.com/vitelitubovuluj/vinuri.pdfIn PDF document text
    • https://s3.amazonaws.com/wupiwupiwot/18338970442.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fa65b25f-fc47-4a2d-9127-75e964be4384/zubugilukozosejavovuseke.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc58fe89955c744b55b026c/t/5fca4852822fbd3263eb1f40/1607092307414/open_camera_android_app_review.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000abbdf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xABBDF 5016 bytes
SHA-256: 739682e08fab7f2aea785f1b3470bfb13044788f71f097f2a83d65db0f7ff21b
font_01_sfnt_off000accb3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xACCB3 11956 bytes
SHA-256: a68f69eabed5c27c464c6db85ab97cca9d69cb2cff4c984eaf3f7f34afbfeab1
font_02_sfnt_off000af42d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAF42D 4324 bytes
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34