Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c54cf6af2e2c6c6…

MALICIOUS

PDF

70.5 KB Created: 2021-05-01 04:25:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 19413dfc9004b48b28065502c5cb9fd3 SHA-1: 2b268abbbc0a867c281972f6a3b78c7ee8b80a94 SHA-256: 8c54cf6af2e2c6c682298b32fc3360bea8a42b1a9987d50572a7709e73989e8a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as a malicious PDF by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The embedded URLs point to various domains hosting PDF files, suggesting a distribution mechanism for phishing or malware. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bestmiamiturf.com/wp-content/plugins/super-forms/uploads/php/files/6fbe333e366d13963eee9e096726afc8/fomozerunitab.pdf
    • https://creationstationdance.com/wp-content/plugins/formcraft/file-upload/server/content/files/16079ce65316ab---fojamubo.pdf
    • https://goldenparadisestsimons.com/wp-content/plugins/super-forms/uploads/php/files/18229a47b74607944326dcf52730cd3a/57297506951.pdf
    • https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080769b1ab24---guxubujike.pdf
    • http://www.redactordecontenidos.eu/wp-content/plugins/formcraft/file-upload/server/content/files/1608700d128bdd---kesawofusirojatisaj.pdf
    • https://caravanandre.it/wp-content/plugins/super-forms/uploads/php/files/050bcdca039d610bf1692218baecc3e5/tosor.pdf
    • http://vasilii-orlov.fun/wp-content/plugins/super-forms/uploads/php/files/c0829a5eea12abe49ce16e115c929632/negukoxipawovudasa.pdf
    • https://www.picmephotoboothhire.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16071c508462f4---23496858238.pdf
    • https://www.kunapak.com/wp-content/plugins/super-forms/uploads/php/files/l6co5111pck4v2bumuc1o9g5j5/65535188046.pdf
    • http://www.patricktennis.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160703118b414d---70420188829.pdf
    • http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c9e859be1b---varuzalovipamu.pdf
    • http://kazenergy.kz/wp-content/plugins/formcraft/file-upload/server/content/files/16080b489370e3---musasumuzeromiv.pdf
    • http://www.sunarsurdurulebilir.com/wp-content/plugins/super-forms/uploads/php/files/d39kea9dpt4107ve8c5cb8hr47/6182667748.pdf
    • http://compie.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160821aa5cbbb7---temujemo.pdf
    • https://www.americanapi.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bd2c12bf62---saxolefejufedudapafemeb.pdf
    • https://www.ptlittleflower.org/wp-content/plugins/super-forms/uploads/php/files/kc2kvs3cf4gcaa4fnnm1bqvluo/saziviwav.pdf
    • http://www.k-24.com/wp-content/plugins/formcraft/file-upload/server/content/files/16088c64bc9c93---1722708774.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=hungry+shark+world+obb+file+apk
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d3d9.bin
5ff387b684d7738ae61ac7d247478341be29e3d733819b5bcf05421b062f7694
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3D9 5660 bytes
font_01_sfnt_off0000e72a.bin
9946542b6092996eff22a5e73e7d26d78a89abdfc7faae335fe787e0b2d39ebf
pdf-font-stream PDF embedded font (sfnt) at offset 0xE72A 11068 bytes