Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d146c27f6e353fa…

MALICIOUS

PDF

104.9 KB Created: 2021-03-21 10:28:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 68aad0e90cbbcab76a6591851d2e225d SHA-1: db80103e4807c660ef70c7f0581f97e983386b15 SHA-256: 8d146c27f6e353fa3b4eb2307bfbc6565130047d8f87913eb67da4d1aa557069
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that appears to be a lure related to fitness, likely leading to a phishing site or malware download. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=how+to+get+big+at+planet+fitness
    • https://cdn.sqhk.co/pozedezupase/2Shdhd1/dewefuwesavutejuzov.pdf
    • https://cdn.sqhk.co/nokikijun/idhdjjh/59104969804.pdf
    • https://cdn.sqhk.co/tipesewete/iaXhfgi/jesadesigojesorovofitij.pdf
    • https://cdn-cms.f-static.net/uploads/4470821/normal_604301535ae85.pdf
    • https://cdn.sqhk.co/nokikifabaf/UxhhY4K/honey_balsamic_chicken_thighs_sheet_pan.pdf
    • https://cdn.sqhk.co/zaviresodew/hjhegji/88633173005.pdf
    • https://cdn-cms.f-static.net/uploads/4366015/normal_601c5e89a4248.pdf
    • https://static.s123-cdn-static.com/uploads/4387040/normal_5fdfce69baf57.pdf
    • https://static.s123-cdn-static.com/uploads/4382961/normal_5ff7a9ea25380.pdf
    • https://cdn.sqhk.co/kafekogi/hh65Kjd/chocolate_cookies_recipe_easy_vegan.pdf
    • https://static.s123-cdn-static.com/uploads/4470683/normal_5ff583aa4bf2c.pdf
    • https://cdn.sqhk.co/mosepoxik/jP7jggf/facebook_marketplace_scams_seller.pdf
    • https://cdn.sqhk.co/xanapaje/oDianhh/wozawufutufoviwikukokup.pdf
    • https://cdn.sqhk.co/kadeposamo/cifjhig/radigepebekozubezolefam.pdf
    • https://cdn.sqhk.co/melipetoluf/9Lmidjb/fixixawuje.pdf
    • https://cdn-cms.f-static.net/uploads/4366337/normal_603022cd2d435.pdf
    • https://cdn.sqhk.co/tetolonul/R7giuhi/benchmade_guided_field_sharpener_review.pdf
    • https://cdn-cms.f-static.net/uploads/4384035/normal_602985b9ef598.pdf
    • https://cdn.sqhk.co/zulatobi/j1Qifhh/jepanibumimazata.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014ee8.bin
3a453869f88b5efacf3a4d1aa8c5d6bae34fb4a37bc6b597d5c67300bf3d3c76
pdf-font-stream PDF embedded font (sfnt) at offset 0x14EE8 4956 bytes
font_01_sfnt_off00015fe5.bin
9993296ac6c427efa0535d0134e87413a410b06a9bf8008584ee903845dc2847
pdf-font-stream PDF embedded font (sfnt) at offset 0x15FE5 12004 bytes
font_02_sfnt_off00018885.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x18885 4324 bytes