Malicious PDF — malware analysis report

Static analysis result for SHA-256 8735ea4913794d23…

MALICIOUS

PDF

85.3 KB Created: 2021-04-16 08:07:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 93233a17a4d006611bbcbdd4c4a682da SHA-1: b0080c4d809619692d783309776a19ed185632b8 SHA-256: 8735ea4913794d23f47a5055eff4c5f49ebe768629f438252cdbf4788e53cfdb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains an embedded external URI pointing to a suspicious domain, which is a common tactic for phishing or malware delivery. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect the user to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/strik?utm_term=how+to.cite+mla PDF link annotation
    • http://about-central.com/75313527200lulb7.pdfIn PDF document text
    • http://cosmosqrab.online/logitech_c525_software_download68y7j.pdfIn PDF document text
    • http://sfhgfje5df.xyz/best_public_speaking_tips_and_techniquesjx998.pdfIn PDF document text
    • http://hayatevesigar.online/bass_tracker_parts_for_saleha7c3.pdfIn PDF document text
    • http://mobile-media.moscow/how_long_does_it_take_to_become_a_medical_coder_and_biller1vw6b.pdfIn PDF document text
    • http://scarcebook.com/megixurizupawnsln.pdfIn PDF document text
    • http://good-production11.site/how_much_is_the_membership_fee_for_planet_fitnessv176q.pdfIn PDF document text
    • http://sport-stavki.fun/executive_personal_assistant_job_descriptioni0wgz.pdfIn PDF document text
    • http://matteset-spon.space/bissell_proheat_cleanshot_2x_user_manualcpcth.pdfIn PDF document text
    • http://itdiscounts.pro/alif_ba_ta_freef60u5.pdfIn PDF document text
    • http://garant-ritual.online/best_ar_15_assembly_lubekf4om.pdfIn PDF document text
    • http://contact-git.top/42050764421zktg8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/lososimap/annadammula_anubandham_movie_songs.pdfIn PDF document text
    • https://s3.amazonaws.com/banula/mole_conversion_worksheet_11-_3_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/woberiz/wupegefajipivosopa.pdfIn PDF document text
    • https://s3.amazonaws.com/mokixetat/ppf_account_in_post_office_online_payment.pdfIn PDF document text
    • https://s3.amazonaws.com/muvazi/60653219774.pdfIn PDF document text
    • https://s3.amazonaws.com/kefodek/boribadopotej.pdfIn PDF document text
    • https://s3.amazonaws.com/rivazixexuguri/48664353126.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001035a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1035A 4436 bytes
SHA-256: 8823a61caa8363bfea17a49e2b1e49899c86454b125054132817e8c6f52656d9
font_01_sfnt_off0001127b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1127B 11276 bytes
SHA-256: c496982650917f3a981903912c8cdf3f846ad64f459856431527a3165261eb7e
font_02_sfnt_off0001389d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1389D 4324 bytes
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176