Malicious PDF — malware analysis report

Static analysis result for SHA-256 8cd16201f38cce75…

MALICIOUS

PDF

111.6 KB Created: 2021-03-07 02:46:20 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-16
MD5: dfe9f57ef0fa60a45f2c5800bd7acaa4 SHA-1: c026d697568f6226ec4c6a8314f8163d9f600e5b SHA-256: 8cd16201f38cce75b4229ab7f4dbbddf8043b56ab7205ba8c79ce8d2e68ddda0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that is disguised as a search query related to Taylor series convergence, likely to trick users into visiting a malicious site. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest it's designed to redirect users to a potentially harmful external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9965

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/strik?utm_term=how+to+find+the+radius+of+convergence+of+a+taylor+series PDF link annotation
    • https://cdn.sqhk.co/rijomawonuj/pdujahf/cake_mania_mod_apk.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4481173/normal_60189f9f570ed.pdfIn PDF document text
    • http://goodshopsales.xyz/how_to_use_pentair_intelliflo_variable_speed_pumpw5g6x.pdfIn PDF document text
    • http://lnstagramsupportlives.com/widazedifivavurezezeruxnket.pdfIn PDF document text
    • https://cdn.sqhk.co/wotirixa/MiaGhiw/41992148225.pdfIn PDF document text
    • https://cdn.sqhk.co/lepavenujal/gcjbhh1/sinozawarip.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4455894/normal_5fe124dc208e4.pdfIn PDF document text
    • http://creditactive.info/kuletijisebon3lji9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4497370/normal_6021724b20566.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4390637/normal_5ff1047b12e4e.pdfIn PDF document text
    • http://curvepreloved.com/damatgdnzx.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4466135/normal_603a1a399333e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4411273/normal_5ff7a39020e63.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4444110/normal_5fe4d2ca9be8c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391642/normal_602ba25ea9b1d.pdfIn PDF document text
    • https://cdn.sqhk.co/zerurukoraju/sqjcmKh/hope_for_paws_rescue_videos.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/fusidejebi/tisajas.pdfIn PDF document text
    • https://s3.amazonaws.com/rorives/79937032356.pdfIn PDF document text
    • https://s3.amazonaws.com/juvetaso/misotefewig.pdfIn PDF document text
    • https://s3.amazonaws.com/xisefowu/ccleaner_pro_apk_android_1.pdfIn PDF document text
    • https://s3.amazonaws.com/goveruduzewoxu/98474962641.pdfIn PDF document text
    • https://s3.amazonaws.com/nelizenejakarug/fakubokipuxumifow.pdfIn PDF document text
    • https://s3.amazonaws.com/pasutiz/anti_cancer_herbs.pdfIn PDF document text
    • https://s3.amazonaws.com/jinotugiwomo/dumodajeva.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000102c3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x102C3 25132 bytes
SHA-256: a95159c5d4c2620fbcf5bd8c03a7f5be65e2543c0d23de9662cb62e8d06b026a
font_01_sfnt_off00014b70.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14B70 5380 bytes
SHA-256: ff5be383868e531f0404a85832373d35c29f3e8f326f4e9a641b68fac9559b71
font_02_sfnt_off00015dcb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15DCB 12880 bytes
SHA-256: 79ce2b01b935ce0f8de375a930fbd247aa003774dc673579598e7224069b8e3d
font_03_sfnt_off00018955.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18955 16860 bytes
SHA-256: b661bd63940cb3b994fc1d7a4e08414eccbec25fa842a5854afe8778cf76eaea
font_04_sfnt_off0001a16b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1A16B 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3