Malicious PDF — malware analysis report

Static analysis result for SHA-256 8fc0f10d9789e699…

MALICIOUS

PDF

76.2 KB Created: 2021-05-05 20:31:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3f5a5a03855948382fa04531c326e343 SHA-1: e450344869eb3c466fead9c1f0267bbfadce4e28 SHA-256: 8fc0f10d9789e699b0fd52734de310d909fcba4598fab1e4633d016d0601ff87
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or social engineering attempt to redirect the user to malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to exploit user trust through a deceptive link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=what+is+gis+in+human+geography
    • http://wibebilija.22web.org/suspicious_minds_book.pdf
    • http://in-step.shop/dos_tipos_de_comunicacion_oral3ak1r.pdf
    • http://passive-income.ru/mackie_1604_vlz3_manual_espaolu2y47.pdf
    • http://xxlmature.site/how_do_i_connect_my_soundpeatss173v.pdf
    • http://pimazisiperej.iblogger.org/kodupisakebalexagufapivix.pdf
    • https://cdn-cms.f-static.net/uploads/4408471/normal_600cf813380c9.pdf
    • http://luwakixifotizim.iblogger.org/mepitobab.pdf
    • http://effektzhizni.ru/lamubowugugugigarivunidqmd4w.pdf
    • http://lemumelubijene.iblogger.org/78666748983.pdf
    • https://cdn-cms.f-static.net/uploads/4461201/normal_606cb98c6d69b.pdf
    • https://cdn-cms.f-static.net/uploads/4411273/normal_603a99131ac6c.pdf
    • https://cdn-cms.f-static.net/uploads/4388174/normal_601afb3d347a3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://duvufewitopemaw.rf.gd/greensleeves_piano_sheet_music_with_letters.pdf
    • https://s3.amazonaws.com/nowonovege/42702666771.pdf
    • http://fewetero.epizy.com/loxawujolu.pdf
    • https://s3.amazonaws.com/posaxugidut/5415132231.pdf
    • https://s3.amazonaws.com/zikeko/biaggi_s_restaurant_nutritional_information.pdf
    • https://s3.amazonaws.com/fofeguj/punctuation_rules_and_practice.pdf
    • http://kuwalenidil.epizy.com/52045064708.pdf
    • https://s3.amazonaws.com/xazarujokemus/character_sheet_template.pdf
    • http://suwuwigo.rf.gd/annona_cherimola_mill.pdf
    • https://s3.amazonaws.com/jolunenafobuw/sipitilijulibuzazexaf.pdf
    • https://s3.amazonaws.com/wifiduxezo/risc-_v_vs_x86_performance.pdf
    • http://xolelapideruse.epizy.com/carcinoma_epidermoide_histopatologia.pdf
    • https://s3.amazonaws.com/difigomisosak/57043362472.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea50.bin
32ab02d07b9e827f30c998ac705829b08469e4a22ed43fb27c6a2e051bda9a5c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA50 5316 bytes
font_01_sfnt_off0000fc4d.bin
edd9a2715bbff4e5a19fd583e8b2253e354f532569188d81d715825dd2e83eb6
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC4D 11476 bytes