Malicious PDF — malware analysis report

Static analysis result for SHA-256 906cff146abce8d1…

MALICIOUS

PDF

86.4 KB Created: 2021-03-12 06:06:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1caaee78102b229b1829fdbe5a32a178 SHA-1: 9d14ca3a76bfe4a571d847c83e7e61a6694697c9 SHA-256: 906cff146abce8d111494bbde77d01b69c811f8aab49b740b599eec2fae7cddc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, strongly suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection further confirm its malicious nature. While no scripts were explicitly extracted, the PDF structure and embedded URI indicate an attempt to trick the user into downloading a malicious payload, likely for credential harvesting or further infection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/award?keyword=web+application+development+proposal+pdf
    • http://chambrely.xyz/61114097976tqzan.pdf
    • http://vevapefin.sportsontheweb.net/93271393266.pdf
    • http://oneitstore.pro/988409204272qppc.pdf
    • http://wabaxifejem.sportsontheweb.net/how_to_change_temperature_on_rinnai_tankless_water_heater.pdf
    • https://wabexerimib.weebly.com/uploads/1/3/0/7/130739061/4fee81e9b529b.pdf
    • http://dotixomovi.sportsontheweb.net/how_to_fix_printer_error_canon.pdf
    • http://ch-bewertung-2888.xyz/51570128317w6rzv.pdf
    • https://betozuwozoz.weebly.com/uploads/1/3/4/1/134108580/1268364.pdf
    • http://salleapp.xyz/aoa_full_form_in_chatb83dn.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f43ea0fb-3eff-47c8-a114-81d3659b3ae5/jorax.pdf
    • https://cc652f91-b1ab-470c-b36f-46d838ef85b2.filesusr.com/ugd/fbccce_d10053dcba864933a60d5eec246b61d3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a0f9e7c1-dd04-4680-afe5-acc60e72cb31/best_will_power_quotes.pdf
    • https://9e269ae7-c3cf-4b9f-bde2-1d9be064b7bf.filesusr.com/ugd/139869_ed47ab17a0dc4b66ae4db55667b9e19b.pdf?index=true
    • https://s3.amazonaws.com/vibuvomomuv/sorotixe.pdf
    • https://uploads.strikinglycdn.com/files/4e7f687e-10df-4cd8-921b-577d215db6d3/sao_light_novel_read_online.pdf
    • https://s3.amazonaws.com/sagotomagin/despacito_lyrics_in_english_and_spanish.pdf
    • https://uploads.strikinglycdn.com/files/32f9fd13-aa2b-4a79-82ef-04a66f52ff52/inferno_novel_by_dante_alighieri.pdf
    • https://923a8ca3-316b-4844-b38f-9bc955ad4852.filesusr.com/ugd/312e0e_4b86b7fb90074ca3acd25ae79dc629eb.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011519.bin
97fb17d6670e527aa34149af3a4e834eeca635753425d5cdd97100b1c4fafcd1
pdf-font-stream PDF embedded font (sfnt) at offset 0x11519 5512 bytes
font_01_sfnt_off000127ce.bin
4524d1fbe106defc9ad7645020d9e31d76cc5b1dd3716ead9f777300658b1d60
pdf-font-stream PDF embedded font (sfnt) at offset 0x127CE 10704 bytes