Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f059f365cbeea70…

MALICIOUS

PDF

109.6 KB Created: 2021-06-07 21:30:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: b0498fb92021f9eb9bc41b8feb680bd4 SHA-1: d7227e927c87c393ca0d5b6672dd115bb3f3c6ed SHA-256: 8f059f365cbeea7055a10619c7f8b4e877755264625ffb7d946960f061cc7579
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ClamAV detection and ML classifier strongly indicate malicious intent. Although no scripts were extracted, the presence of an external URI and the overall classification suggest a phishing attempt disguised as a helpful document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7570

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crewmak.ru/pbw?utm_term=english+verbs+list+with+gujarati+meaning+pdf PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4409255/normal_5fc6de45592ed.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389080/normal_5fe766708451f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4428329/normal_6032495887e33.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4427506/normal_6029638c40e30.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455374/normal_60229f864431b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4457272/normal_5feb8eb475770.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4368246/normal_5fcc835bd69cf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4383334/normal_604e48b5059bf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4503791/normal_602d6bad5b87f.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://uploads.strikinglycdn.com/files/b0ed3ae7-94de-42cd-9f9b-00f8c45c73b0/dream_meaning_snake_bites_dog.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/28dd5831-2724-4616-aded-a0e314d30b57/29393538291.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/def0a404-03b7-4557-96a3-91fda85cb226/what_is_a_fastidious_bacteria.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a63e9bdb-4cd4-49b1-aeb6-2d44ca2dcc33/37250816014.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f92fe8d5-6085-4938-9763-05363c3f26c2/fevusugiz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/efd6bcb6-69a9-4ec6-a310-d3a71781478b/zivuxaxisofo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6fd6ddef-fa80-4cb3-bb75-7af48c7e7323/78004674180.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c745db8c-5faa-4fc6-919e-12cc53fcca14/603959421.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cb806f55-1d9a-4260-80a3-db9c38de3457/resuxakuwiloketowute.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017117.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17117 5780 bytes
SHA-256: dc23ec3b73f55fe3d2cc489538a2563e6bcf2774bbb49891e531c0228e54de0a
font_01_sfnt_off000184af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x184AF 11640 bytes
SHA-256: 24568c5ba5c3d076fee5efbfdf4473dc2b07f9eb12a8e8c77d9a8924340d1944
font_02_sfnt_off0001ac92.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1AC92 3868 bytes
SHA-256: b9548a2ba8c7365f16cfeeb9c02e6106c045d076d15c770940518fd23ed145bf