Malicious PDF — malware analysis report

Static analysis result for SHA-256 90b72ff385488da1…

MALICIOUS

PDF

67.8 KB Created: 2021-05-11 15:13:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3dcc81e56d6682e76fe289252a7f1925 SHA-1: 847156840dcf4fcb69cd71e35798cf96b4c1a3a3 SHA-256: 90b72ff385488da198d1769a0f3cd93d09c2d9fbb50f6da9da58cde13601cc07
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating the presence of an external URI. While the document body is heavily obfuscated, the embedded URL points to a PDF file hosted on a suspicious domain, suggesting a phishing or malware distribution attempt. The presence of multiple similar PDF URLs further supports this conclusion.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8846

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vmkstroi.ru/wp-content/plugins/super-forms/uploads/php/files/ce08dbd395f8f8fbbc3166bd8874db39/4412228916.pdf
    • https://creationstationdance.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074f784ac2f3---93268162509.pdf
    • https://amkboiler.com/wp-content/plugins/super-forms/uploads/php/files/dq51dm8rcoph9um51ur7murr08/85251006958.pdf
    • http://jnnycc.org/userfiles/file/rekilu.pdf
    • https://yidinfo.net/wp-content/plugins/super-forms/uploads/php/files/88bfju1qqgr33i7sogfp7gulrq/76303482748.pdf
    • https://www.justgym.co.za/wp-content/plugins/super-forms/uploads/php/files/s18mpsbgtd8ia2rj1qdu8sdb1t/26099342720.pdf
    • https://agribusiness.pk/wp-content/plugins/formcraft/file-upload/server/content/files/16086885a318a1---rugipazi.pdf
    • https://southernlightingsource.com/wp-content/plugins/super-forms/uploads/php/files/6c6b0d0f538b79f5ed032378263497cb/rajagutoj.pdf
    • https://admonks.ru/wp-content/plugins/super-forms/uploads/php/files/77d06d77558a6f56e99d75b29b41561e/soxemerirelox.pdf
    • https://gpuhub.net/wp-content/plugins/super-forms/uploads/php/files/mh5dgv8ka2tldtmtn3acqtiruv/87520262079.pdf
    • http://www.liveartsaskatchewan.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609672707d44c---xotisosimagigaxujixepase.pdf
    • http://www.siscard.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607bbf701d3c3---rodoputekeduzitopug.pdf
    • https://balance-global.com/wp-content/plugins/super-forms/uploads/php/files/fb3cb3uruebb3kcjfq1ju8it0k/64292227558.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609892b257a32---manojufapegolivoru.pdf
    • https://seroinstitute.com/wp-content/plugins/super-forms/uploads/php/files/c0778247ea0fc7133e323f1bb21c0bad/83312351906.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/ngfLrbzwjls/uplcv?utm_term=beginner+english+vocabulary+exercises+pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ddd9.bin
25a16c0d02727589788e7bb6766471c95bd42092ca27e8cfcc22504439b8d986
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDD9 5836 bytes
font_01_sfnt_off0000f1c4.bin
a06493421e698fd13f16d6dd24554570a0d313bbe4d3f3000cedc1debec985ad
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1C4 10208 bytes