Malicious PDF — malware analysis report

Static analysis result for SHA-256 926a6159d930c33b…

MALICIOUS

PDF

83.4 KB Created: 2021-03-19 07:26:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e95e264b31b9a2e23a4b5f8aa6baaf36 SHA-1: 6a98e078f07d8df0280a2c519af131196933d7e9 SHA-256: 926a6159d930c33b90598f5b5950e7c0ab99480b40e2e1d5b5b2f5531be1b39c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that points to a suspicious domain, likely intended for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest it's designed to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=power+bi+boolean+search+strings+for+recruiters
    • https://nomikevokatipo.weebly.com/uploads/1/3/1/8/131859895/34feee8cf60.pdf
    • https://roturusuwanowus.weebly.com/uploads/1/3/4/3/134363773/8fe448d.pdf
    • https://woxumonukoke.weebly.com/uploads/1/3/6/0/136090180/019a467d.pdf
    • https://cdn-cms.f-static.net/uploads/4473926/normal_6011c846b4fb4.pdf
    • https://static.s123-cdn-static.com/uploads/4503692/normal_5ff58fc48d91d.pdf
    • https://cdn-cms.f-static.net/uploads/4413228/normal_605331f5dfbe2.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wulotugadag/buxepasatik.pdf
    • https://uploads.strikinglycdn.com/files/ceb2b2b2-63c9-4481-bc2a-fc0ee6605ef7/krups_egg_cooker_measuring_cup.pdf
    • https://s3.amazonaws.com/kavalukato/interstellar_main_theme_piano_sheet_free.pdf
    • http://daxokefi.epizy.com/fairy_tales_hair_care_walmart.pdf
    • http://gerifanonejuvad.rf.gd/ladies_block_heel_platform_shoes_uk.pdf
    • http://keporeninudo.rf.gd/wixozabusuvifijavarita.pdf
    • http://xumuturil.epizy.com/how_to_do_istikhara_for_university.pdf
    • https://uploads.strikinglycdn.com/files/f2dd8bea-f5ca-4e06-b620-cbd5e10b517b/how_to_set_totaline_thermostat.pdf
    • https://s3.amazonaws.com/dozuga/aap_ka_suroor_song_320kbps.pdf
    • https://s3.amazonaws.com/jifedefujodu/best_performing_australian_blue_chip_shares.pdf
    • http://vevuberi.epizy.com/letter_to_confirm_employment_and_salary_template.pdf
    • http://pekufupudemolor.epizy.com/ancient_civilizations_grade_4_worksheets.pdf
    • http://zevofelajasuz.epizy.com/68331374166.pdf
    • http://japefafe.epizy.com/jukolawanodujitapetati.pdf
    • https://uploads.strikinglycdn.com/files/135d0776-2b28-4c3e-b4fe-72ca6ae88483/what_is_the_best_compact_washer_and_dryer.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000106c3.bin
ae1ede2b246b35c0ac357d3836f1d2d70fd8811549d41dfc8a4589384711e181
pdf-font-stream PDF embedded font (sfnt) at offset 0x106C3 5376 bytes
font_01_sfnt_off0001191f.bin
0ce9d5e2d6b1c6f5eb4805868d05b0b01d0c148b337e3b5ed208f8db054e0117
pdf-font-stream PDF embedded font (sfnt) at offset 0x1191F 11440 bytes