Malicious PDF — malware analysis report

Static analysis result for SHA-256 93f928a6da115d9f…

MALICIOUS

PDF

69.9 KB Created: 2021-03-07 22:57:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4d10c85a50664aee430a5d7b14e81d5 SHA-1: d1199bd35de57e26c756ed49d8cac2f70eee0f57 SHA-256: 93f928a6da115d9f70437e7b9ab002a741bdb6ef1032b489cb93e7d2c0212361
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to a suspicious domain, likely used to host malicious content or phishing pages. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to redirect users to potentially harmful external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=judy%2527s+country+kitchen+fairburn+ga
    • http://instas.site/42746468980qlx2a.pdf
    • http://1xbet-sportstavki.fun/cinderella_solution_main_booklkjoi.pdf
    • http://xabusiwidurej.22web.org/xizewup.pdf
    • http://vuwefedope.sportsontheweb.net/dcs_world_mission_editor_escort.pdf
    • http://rikafitamedad.medianewsonline.com/vagevifurenobupujakurelu.pdf
    • http://mibemuxagegija.mywebcommunity.org/49047008690.pdf
    • http://plsale.pro/abu_garcia_black_max_baitcast_reel_reviewt9qxp.pdf
    • http://zegoves.22web.org/27227791547.pdf
    • http://towufato.mywebcommunity.org/how_to_score_wiat_iii_essay.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://mubozezubudiz.rf.gd/bobujejujapupisejipenobex.pdf
    • http://senixanuxulas.rf.gd/19_home_maintenance_pro_tips_for_winter.pdf
    • https://c7f0abc7-d23b-482d-bd16-0771495bb668.filesusr.com/ugd/bb13a2_47d599451d7f4d4a8ec5196f5cb2bb17.pdf?index=true
    • http://wurasegato.rf.gd/cheap_robot_vacuum_cleaner_for_sale.pdf
    • http://wuluminibopa.rf.gd/62897188420.pdf
    • http://xakagigoneliv.myartsonline.com/lavubu.pdf
    • http://nesitojogosew.epizy.com/2430866574.pdf
    • https://c63ca81c-6df4-4ec3-bc2e-8508f29a6879.filesusr.com/ugd/d48fe3_b96340167a0b47d990b309b66a93a9bb.pdf?index=true
    • http://difavaxegugadu.epizy.com/3169876633.pdf
    • https://9d76d0c6-5807-43ac-a2ba-7b4112d1a20a.filesusr.com/ugd/5cd33b_d625a9e0c96a4f34ad90d6ef2e72d889.pdf?index=true
    • https://6478d21b-237c-41b5-add8-96d7b9819624.filesusr.com/ugd/c7ef1a_fb3d04034e2f484a990e5a40a21c067f.pdf?index=true
    • http://wedutatitupaze.epizy.com/acer_chromebook_11_specifications.pdf
    • https://b5c90759-dbf8-4ccd-b12d-e23c958527f9.filesusr.com/ugd/915a55_343357e1f0d54be0a56343a32cc65769.pdf?index=true
    • http://zudovub.epizy.com/kapomeveledaladi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d391.bin
6571c178934414326f0ff873372bfe6212560a2ddf90f7056d1fa38a0c22cebc
pdf-font-stream PDF embedded font (sfnt) at offset 0xD391 5580 bytes
font_01_sfnt_off0000e69b.bin
bd5a263251397ae699fccab765601bff96afebf296045ead871d4a2170479764
pdf-font-stream PDF embedded font (sfnt) at offset 0xE69B 10412 bytes