Malicious PDF — malware analysis report

Static analysis result for SHA-256 88af37799fd5a608…

MALICIOUS

PDF

72.9 KB Created: 2021-03-17 06:31:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 88c024b7e5c76fba0241088205c2e31f SHA-1: b1de602f6b1ac44f5970561730f2ed99befda0e4 SHA-256: 88af37799fd5a60881af8dc8b4511bc483f7f15764a9a13f16e54ef50d1c4181
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI that redirects to a URL designed to appear as a search result for educational materials. This URL is highly suspicious and likely leads to a phishing or malware download page. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/award?keyword=oxford+phonics+world+1+flashcards+pdf
    • https://tixaradizu.weebly.com/uploads/1/3/4/6/134652762/valibetulebar.pdf
    • https://nejalebemenogun.weebly.com/uploads/1/3/1/0/131070187/6672754.pdf
    • http://sandiego-podcasts.com/wafumufepobazokddbu.pdf
    • http://zumepaposakuf.scienceontheweb.net/vasovagal_syncope_patient_information.pdf
    • http://copyright-services-us.com/what_personality_types_get_along16w8e.pdf
    • http://meetdouche.xyz/wazapogurco0.pdf
    • http://rekijiwowak.scienceontheweb.net/may_2020_weekly_calendar.pdf
    • http://warowusavi.mywebcommunity.org/60504865296.pdf
    • http://shopee24.site/minecraft_world_map_download_1._14p1ox4.pdf
    • http://alexandreablog.com/hollywood_movies_mp4_moviezzgq0w.pdf
    • http://mailedflkf.site/autocad_gratis_students55wa.pdf
    • http://mavito.online/12685968577u5ola.pdf
    • https://pomaripo.weebly.com/uploads/1/3/0/9/130969966/molemegozafadet.pdf
    • http://zoxodur.sportsontheweb.net/does_buffalo_wild_wings_do_grilled_wings.pdf
    • http://fazejajogavu.medianewsonline.com/how_long_will_an_ecg_take.pdf
    • http://pixunune.sportsontheweb.net/99438240327.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://segurixuzek.myartsonline.com/tevifolimuxavoniwixedekol.pdf
    • http://filosoko.onlinewebshop.net/bayesian_machine_learning.pdf
    • https://s3.amazonaws.com/jimugivos/49096412132.pdf
    • https://s3.amazonaws.com/pilazi/49076962078.pdf
    • https://s3.amazonaws.com/vatosolikijike/sawopig.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cfc2.bin
83561cb71cf680eccaf8dd3a2888ee107847c0c1edc8adaa06235ff6231a26ac
pdf-font-stream PDF embedded font (sfnt) at offset 0xCFC2 5484 bytes
font_01_sfnt_off0000e283.bin
f623315d62b159208fbd923b422564b76671c49c43ef3d727644c7da3b563545
pdf-font-stream PDF embedded font (sfnt) at offset 0xE283 18628 bytes