Malicious PDF — malware analysis report

Static analysis result for SHA-256 90a8112231e4a609…

MALICIOUS

PDF

89.7 KB Created: 2021-05-22 05:48:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: c11689b9a65b293fbf408b9053d08579 SHA-1: 51aed00d6e899367d975bcd9d3b4b1f012db5be2 SHA-256: 90a8112231e4a6099a526916f7fde73828965d9f067e208df28d962bf06c534f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URL pointing to a suspicious domain, which is a common tactic for phishing or malware delivery. The PDF structure and embedded content suggest it's designed to trick the user into visiting the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/strik?utm_term=what+are+the+responsibilities+of+a+pmo PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4366660/normal_600e4f0e03bde.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403276/normal_5fee001e7796c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4490250/normal_6062750de0bdd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450426/normal_604459e11f4cb.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4366385/normal_5fee396ee1c7c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454163/normal_60330d1982693.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4492245/normal_600e649173961.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4460686/normal_600448ffcbde3.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/belapawerezuju/gexizofoledagazobaguru.pdfIn PDF document text
    • https://s3.amazonaws.com/lopadivupudexa/psychosis_creepypasta.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3b37f5e6-57cc-487e-bd9c-c3a94619a072/negekidozupibomifuzirogo.pdfIn PDF document text
    • https://s3.amazonaws.com/dewazewokib/rogemoregikujanelimadi.pdfIn PDF document text
    • https://s3.amazonaws.com/werowibovezoje/what_is_the_life_of_a_nuclear_power_plant.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/83d7af0b-9a93-483b-9920-ede7fc34adf3/97101641651.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/95f5b999-d7f2-47c7-9a20-b1584d00f722/implementing_an_iso_13485_quality_management_system_for_medical_devices.pdfIn PDF document text
    • https://s3.amazonaws.com/kezemiradigu/90910244243.pdfIn PDF document text
    • https://s3.amazonaws.com/tujeviwakirawu/fgo_camelot_final_boss_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c7982487-072e-4586-8e13-11380e42a4cc/dialektik_der_aufklrung_hrbuch.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3a468c70-9e6b-49c4-966c-0010cf918146/mimemulowaxes.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011f03.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F03 5292 bytes
SHA-256: 0734545abcc098de9aeaccc18f457b68d5708044373bded2a4a80d6657a2ca59
font_01_sfnt_off000130e2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x130E2 12380 bytes
SHA-256: 21c7b5a4d3772808cefb64fbc25d8d9bb311775b564223882064828cfe830e28