Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c3d867bef43bee0…

MALICIOUS

PDF

76.4 KB Created: 2021-03-29 14:16:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d7119012bfbe2a01b5083aa21e81f89d SHA-1: 79ba887d1a11ebee20e2a25651f8803e6877b333 SHA-256: 8c3d867bef43bee0a7a18e41f32fe8deb312bb658655e7f6107482a0561d0410
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were directly extracted, the PDF structure and embedded URI are indicative of a lure to a malicious website, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=money+making+guide+runescape+2017
    • http://good-production20.site/how_often_should_i_brush_my_teeth_to_whiten_themc4i17.pdf
    • https://cdn-cms.f-static.net/uploads/4490141/normal_5fd350702f3af.pdf
    • http://linza.media/simply_piano_by_joytunes_download_pcv2hff.pdf
    • https://cdn-cms.f-static.net/uploads/4383703/normal_6054816f9d238.pdf
    • https://static.s123-cdn-static.com/uploads/4483587/normal_5ff3d156af38b.pdf
    • http://amst-watch-v2.club/proform_6.0_rt_treadmill_price3b0zn.pdf
    • http://stepka2016.xyz/much_ado_about_nothing_characters_relationshipz4gyf.pdf
    • http://datingdate.site/rojofujafotuwulnqg88.pdf
    • https://cdn-cms.f-static.net/uploads/4470964/normal_5fea248fb8aaa.pdf
    • https://cdn-cms.f-static.net/uploads/4495681/normal_604988563fd19.pdf
    • https://cdn-cms.f-static.net/uploads/4425910/normal_602c31cb0a03d.pdf
    • https://cdn-cms.f-static.net/uploads/4451754/normal_6045058a02abd.pdf
    • http://devlp.design/which_statement_or_statements_accurately_describe_a_good_way_to_avoid_excessive_service_feesdcpgk.pdf
    • https://cdn-cms.f-static.net/uploads/4452148/normal_6056349387bbf.pdf
    • https://cdn-cms.f-static.net/uploads/4453326/normal_603a52b4c4229.pdf
    • http://laura-egorova.ru/towopuzmvivu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/6348ff87-0885-4819-a416-38c00cbee6ee/jibugewerinenilaw.pdf
    • https://uploads.strikinglycdn.com/files/77cc76e6-f06e-4e3a-bd05-bd2e99184924/33959264218.pdf
    • https://uploads.strikinglycdn.com/files/ae7378d7-3b20-4b0f-bd2e-420aa8f62706/45201969077.pdf
    • https://uploads.strikinglycdn.com/files/e758afad-f46c-4bc8-9cc9-a0a5f658b273/libro_la_metamorfosis_de_franz_kafka_resumen.pdf
    • https://uploads.strikinglycdn.com/files/29ec0474-50f9-4fd9-bedf-25cc4b4e160f/what_is_leading_change_adding_value.pdf
    • https://uploads.strikinglycdn.com/files/fdbc6e03-4614-404e-9a86-e41f18d789b8/77410617767.pdf
    • https://uploads.strikinglycdn.com/files/10dbc15c-0d8f-4197-90d6-5608c0e59a45/how_to_make_a_good_origami_paper_airplane_in_the_world.pdf
    • https://uploads.strikinglycdn.com/files/acc25cfa-3954-441e-b332-2896b9179055/49589349504.pdf
    • https://uploads.strikinglycdn.com/files/d0ca08ca-ed38-45b0-afee-f44e17819fd5/56966651015.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df13.bin
c82dcbde6d6df9c620765bffc840f89194226d0829466d109f1b0cb5a6f1453d
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF13 5740 bytes
font_01_sfnt_off0000f298.bin
ec1bd0400498ff9bdc54b8f593de383564c14452582465bd16593a0cb8541bbf
pdf-font-stream PDF embedded font (sfnt) at offset 0xF298 10348 bytes
font_02_sfnt_off000115d9.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x115D9 4324 bytes