Malicious PDF — malware analysis report

Static analysis result for SHA-256 896837ce32cdc3d9…

MALICIOUS

PDF

75.2 KB Created: 2021-05-23 08:43:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: bce2dc79759de875fffba3044e1f4548 SHA-1: 922f2206a842fbc108b0842b87787202be8fc548 SHA-256: 896837ce32cdc3d9e5d8cc2378a4105813bae85c057c057e550f8d860d6259e4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=medical+terminology+pdf+2020 PDF link annotation
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/52904790-9c90-46db-93de-b3bd3c70a18c/marantz_nr1506_receiver_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/52388b18-2b8b-44ce-94df-1113678cfaf4/kuzavuz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/35dfa988-6733-4ae3-b486-80a9ea90e1a0/satetigid.pdfIn PDF document text
    • https://s3.amazonaws.com/medaliwifufugel/61997441743.pdfIn PDF document text
    • https://s3.amazonaws.com/zarusegibitumet/jumurewapimimakobuvox.pdfIn PDF document text
    • https://s3.amazonaws.com/xakusineba/accident_report_form_template_south_africa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/afaa2925-f160-4148-aa34-fa445ed11f90/2012_jeep_grand_cherokee_limited_wheel_size.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1499d935-0931-46a1-ba5d-2474ec4e00ac/50787878577.pdfIn PDF document text
    • https://s3.amazonaws.com/wibedubosateg/43095399034.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5838f01-c978-46b1-bc30-3795f7cb4909/55947852419.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bba1f2dd-997a-449c-a787-6a6edf44b1ad/geometry_chapter_1_test_b_answer_key.pdfIn PDF document text
    • https://s3.amazonaws.com/lewuli/dagannoth_kings_trio_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c45053ec-3bac-4dfc-b4b3-ce7123a04ed3/joturebuporise.pdfIn PDF document text
    • https://s3.amazonaws.com/muvemasoxaji/72942466979.pdfIn PDF document text
    • https://s3.amazonaws.com/zesixefe/is_my_hp_deskjet_3050_printer_airprint_compatible.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a4aaa15e-ed17-4119-80ea-783840a97162/buziguvoxusomese.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/912e7936-9001-4692-b00f-8388685760ec/best_podcasts_for_learning_philosophy.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/99b63dfa-7754-42bc-936a-70ee82aadad9/49427921062.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cbbda256-a8bf-47de-871d-43d6bc6ccea2/how_to_master_hip_hop_in_logic_pro_x.pdfIn PDF document text
    • https://s3.amazonaws.com/piwanisaj/fabamod.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36fb130b-b0af-49b2-b8c2-a9e08910bbb6/3650880140.pdfIn PDF document text
    • https://s3.amazonaws.com/padosumifubobo/63948749415.pdfIn PDF document text
    • https://s3.amazonaws.com/rogugagatuf/blood_group_test_app_for_android.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7735d87e-6a72-4543-834a-d22727f6f39d/can_microsoft_office_be_installed_on_ipad_pro.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e859.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE859 5680 bytes
SHA-256: cf3bd3ecfe4e55d961238042ccf77683ecb7a171ac29a825398373146cb927ca
font_01_sfnt_off0000fbb1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFBB1 10516 bytes
SHA-256: 5872c3dbbc0bc6332f07f89863bf026bdff0ead5d9431116f8bf344cc9f025db