Malicious PDF — malware analysis report

Static analysis result for SHA-256 8bfea5edfe002f0c…

MALICIOUS

PDF

81.1 KB Created: 2021-03-02 00:59:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e50b81bae23234b3ac4820c6b727d560 SHA-1: 5bcaf3f8cf29159296b4e1bca113aa661975b5d5 SHA-256: 8bfea5edfe002f0ca3e129ede42d83289e40f5e9c06b8a8ed6c77f9330e62ba8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest it's designed to redirect users to a malicious site, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=devilbiss+pressure+washer+unloader+valve
    • http://rent-nout.site/wordpress_admin_panel_not_openingzbgwo.pdf
    • https://cdn.sqhk.co/nakokixega/eQgdNgd/80362358914.pdf
    • https://cdn.sqhk.co/botikavanov/ffijhcg/jaxofarukeveginafokusit.pdf
    • http://gimepar.22web.org/barcelona_vs_chelsea_highlights.pdf
    • http://wojurimaxab.mywebcommunity.org/24249321099.pdf
    • http://dwatches.site/159877444209h4a0.pdf
    • http://service-hire.com/aion_bard_guide_pveue8aa.pdf
    • https://cdn.sqhk.co/zogowefu/UgfEiaB/pevevamatadafunoxigogufu.pdf
    • http://raxejudesezix.scienceontheweb.net/telewo.pdf
    • http://zegererevez.medianewsonline.com/21564537321.pdf
    • http://marafonsport.site/86727225703c1m4r.pdf
    • http://vikiduxa.mywebcommunity.org/the_negro_speaks_of_rivers_poem_analysis.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://mimumugemefes.epizy.com/essential_oils_reference_guide.pdf
    • https://s3.amazonaws.com/godoremitiwuja/tamil_album_video_songs_2018_audio.pdf
    • https://s3.amazonaws.com/mudurixo/defuvepagaso.pdf
    • http://zoluwupaxefiv.rf.gd/ranezogotuxo.pdf
    • https://s3.amazonaws.com/pafexegud/mabigolojadaxulavo.pdf
    • https://s3.amazonaws.com/nazekisigiduz/hungry_shark_world_map_guide.pdf
    • https://s3.amazonaws.com/nitajosasa/86847537625.pdf
    • http://sajoveguduv.onlinewebshop.net/dixie_chopper_silver_eagle_2750_oil.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1de.bin
09360ad34a9ede525d47467e4b2d2e5e74fff718f60e568d1edbdd1ee6e47ca0
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1DE 5140 bytes
font_01_sfnt_off0001034f.bin
bbcada351f12d81042b7415765fa9758705b67f84a8c27dfbf27acc4dd8be087
pdf-font-stream PDF embedded font (sfnt) at offset 0x1034F 11104 bytes
font_02_sfnt_off000128a0.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x128A0 4324 bytes