Malicious PDF — malware analysis report

Static analysis result for SHA-256 8dd559a72ba3b25f…

MALICIOUS

PDF

91.8 KB Created: 2021-03-19 23:36:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: d6f08d217c723735d73fe8ea812c3774 SHA-1: b00936cb07f67b11ccc951761f5adee066fd6278 SHA-256: 8dd559a72ba3b25f7eee9f105e44a58d88c6f48c16838e93458b5eeb4e9e4ffc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/123?utm_term=american+english+file+2+answer+key+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4449402/normal_604fd64fb3778.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4451348/normal_5feb6bc6065cf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4487623/normal_6013ac1dd0220.pdfIn PDF document text
    • http://vuwiwetidajin.mywebcommunity.org/how_to_use_procreate_app.pdfIn PDF document text
    • http://wumewil.sportsontheweb.net/how_to_install_extend_to_fit_forward_facing.pdfIn PDF document text
    • http://rulabepotinujeb.mypressonline.com/40649210012.pdfIn PDF document text
    • http://zurujavurobe.scienceontheweb.net/written_in_my_own_hearts_blood_audiobook_free.pdfIn PDF document text
    • http://xufamorazogubov.sportsontheweb.net/wastewater_treatment_g._l._karia_free_download.pdfIn PDF document text
    • http://vadosixajobirug.mygamesonline.org/fallout_4_bobblehead_stand_mod.pdfIn PDF document text
    • http://zakewabo.scienceontheweb.net/app_para_aprender_ingls_gratis_sin_internet.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4386606/normal_5fde5ae3ad555.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://6dd05bf8-a32e-4ce7-8057-9a1894012cff.filesusr.com/ugd/4ce960_037fe5a87e21422b996f4ece5fa29b6c.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/jusuberu/43375377084.pdfIn PDF document text
    • https://s3.amazonaws.com/lezopobigeza/kiwewifekixiforigope.pdfIn PDF document text
    • https://ca39a19f-16f9-469f-ab0b-65ec0463b8d0.filesusr.com/ugd/cc9b97_7260f495b43846acbd3566591ed893b5.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/feliso/nikon_d850_dslr_fx-_format_camera.pdfIn PDF document text
    • https://0a37a3d5-a0bf-4e77-8ff5-6127fd08aefa.filesusr.com/ugd/6046c9_30c527aa23e74428b53972df00ea675a.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/nilafafakem/vosatobukozijudisixebuf.pdfIn PDF document text
    • https://s3.amazonaws.com/fezenur/kaleshwaram_project_photos.pdfIn PDF document text
    • https://1dab3517-3db0-43ff-9fd6-b65b51f65b60.filesusr.com/ugd/565485_fb65face1e6744c7a208b78e19024a3d.pdf?index=trueIn PDF document text
    • http://refusunono.onlinewebshop.net/94456471418.pdfIn PDF document text
    • https://160e4e15-e27a-4ef2-9b26-f67fc0969a86.filesusr.com/ugd/cbdbb6_d11743ad8efb42a58a910798951c362a.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011b3d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11B3D 5948 bytes
SHA-256: d8fd1d8767fc5d4275fe4ca74507a3bb40b00ec9d581710c23d68003c07dcffd
font_01_sfnt_off00012f73.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12F73 15528 bytes
SHA-256: 304c94ab362ac1909886f2aa23111377afd788083551d3342f6ac1b455237db2