Malicious PDF — malware analysis report

Static analysis result for SHA-256 89cff98318cfa084…

MALICIOUS

PDF

68.3 KB Created: 2021-03-25 10:28:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 53f54d4d260f437baa1c8455c65350bf SHA-1: ee4cd680ac851bba60252278b7e8545bcaeba8bd SHA-256: 89cff98318cfa0842f5c97d6bb4c5a904ea2f1249d1d246769bf43f84b328386
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that redirects to a malicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest it's designed to exploit users by presenting a seemingly innocuous document that leads to a harmful external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=holmes+tower+fan+manual PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4368760/normal_5ff755c021f98.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4424696/normal_604e7f00902b2.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4479938/normal_5ff443fb04b48.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404285/normal_5fe811d1eb742.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369304/normal_603890f48f904.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4374021/normal_5fdd45603986c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4414489/normal_60078e2be9b5b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4410976/normal_5fec8ca397337.pdfIn PDF document text
    • http://penutiponexeb.iblogger.org/blank_music_sheet_a4.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470828/normal_6000324fadb2b.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/0956f62a-51be-4c74-aa93-e297d63c6368/69749620798.pdfIn PDF document text
    • https://s3.amazonaws.com/banula/social_media_marketing_strategy_thesis.pdfIn PDF document text
    • https://s3.amazonaws.com/gowebabuxogiro/90408739694.pdfIn PDF document text
    • https://s3.amazonaws.com/gomakobez/all_my_sons_moving_nashville_reviews.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b85db94-8775-456f-9a2e-2002ab73f3a4/41281123584.pdfIn PDF document text
    • https://s3.amazonaws.com/mexavofezoxi/46692476839.pdfIn PDF document text
    • https://s3.amazonaws.com/loranoduzuja/sat_subject_test_literature_score_chart.pdfIn PDF document text
    • http://wememone.rf.gd/pathophysiology_of_amoebiasis.pdfIn PDF document text
    • https://s3.amazonaws.com/mudurixo/monster_vs_aliens_2_full_movie_in_hindi_download.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d0c0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD0C0 4964 bytes
SHA-256: e7ca1089f2a1db38d4fbeca6d65d7f6f465f0289dc53500f5f4008afd6078ed6
font_01_sfnt_off0000e197.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE197 10164 bytes
SHA-256: 7f4a3ddb92b78b8602243cff74fb77672d01276c65d89b819e61bfefcbf4cdd7