Malicious PDF — malware analysis report

Static analysis result for SHA-256 8f286e4a86a4141b…

MALICIOUS

PDF

95.2 KB Created: 2021-03-05 08:09:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c86f12729604be226c92eb75dcb95f00 SHA-1: e5e34b4d56236a2c83e53e0266485b9054a687f2 SHA-256: 8f286e4a86a4141b8094ccc9afac6495205ae7d80e20e2102fef828b72f718f7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains an embedded URL that mimics a search result, likely to trick users into clicking it. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URI heuristic suggest it's designed to lead the user to a malicious resource, potentially for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=what+is+resistor+color+code
    • https://cdn.sqhk.co/wesegagage/hagegiH/47631378444.pdf
    • http://luminar4-download.xyz/how_to_determine_whether_an_acid_is_strong_or_weakquaq7.pdf
    • http://goldstein.berlin/dabupolipegivukis92td.pdf
    • https://static.s123-cdn-static.com/uploads/4366029/normal_5fe3111b23a7e.pdf
    • http://zaparipajomigi.scienceontheweb.net/what_age_high_chair_until.pdf
    • https://cdn.sqhk.co/wudarivat/g2mVbgj/triblive_best_of_the_best_2020.pdf
    • http://sukutoxuwurif.mywebcommunity.org/aw_tozer_devotional_app.pdf
    • http://xobokalute.iblogger.org/fupavuxos.pdf
    • https://cdn.sqhk.co/pujixefan/ejaMhi6/morality_play_literary_devices.pdf
    • https://cdn-cms.f-static.net/uploads/4500199/normal_602d6aed2570d.pdf
    • https://cdn.sqhk.co/bupitagalir/iaieigW/my_boy_gba_emulator_latest_cracked_apk.pdf
    • http://afracheat1.xyz/chinnamasta_hd_images3tv1c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://gumomexad.onlinewebshop.net/zebuzabirinedawodifomoxut.pdf
    • http://gidimuni.epizy.com/write_work_experience_report_sample.pdf
    • http://wikatefa.epizy.com/shipping_label_template_ups.pdf
    • https://s3.amazonaws.com/midizaxopazeji/lofepapoditonowabipiso.pdf
    • https://s3.amazonaws.com/jajoxulabojaso/kivofuwadipopod.pdf
    • http://fosofeba.rf.gd/surah_maryam_urdu_translation_mp3_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012bf9.bin
9e2c4868e1077bffd06361f8120b0d8cb41735fa16dfe942555d3c94a6119dac
pdf-font-stream PDF embedded font (sfnt) at offset 0x12BF9 4724 bytes
font_01_sfnt_off00013c1e.bin
56210e9ddf838c235a6808c411c8d0bac149d3bf2aa0666c71f33b0e6aeb9a65
pdf-font-stream PDF embedded font (sfnt) at offset 0x13C1E 10944 bytes
font_02_sfnt_off00016188.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x16188 4324 bytes