Malicious PDF — malware analysis report

Static analysis result for SHA-256 94116abdd7570810…

MALICIOUS

PDF

77.1 KB Created: 2021-04-06 17:39:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 142e3f2c93a2dc7d4bfc64b5cf5c3c3a SHA-1: d7f4d7e27711efb9aac73640d7cc3b986b212b94 SHA-256: 94116abdd75708109924b1ee19496a4cde2be9a9f608fb9fdc912b21c5918a77
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that redirects to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, contains references to the embedded URL, reinforcing the phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=definition+of+library+and+information+science+pdf
    • https://jeludumekidi.weebly.com/uploads/1/3/2/7/132740852/276754.pdf
    • https://cdn.sqhk.co/kidimezamos/jcehdhf/8676507825.pdf
    • https://cdn-cms.f-static.net/uploads/4453901/normal_605527694c996.pdf
    • https://cdn-cms.f-static.net/uploads/4482027/normal_6032bfe8df51e.pdf
    • https://vojizozovogimum.weebly.com/uploads/1/3/0/7/130740342/5431260.pdf
    • https://cdn-cms.f-static.net/uploads/4476446/normal_6029b0cfe076c.pdf
    • https://cdn-cms.f-static.net/uploads/4470524/normal_60279062a9e6c.pdf
    • https://cdn-cms.f-static.net/uploads/4501993/normal_6061ddd739bd6.pdf
    • https://cdn.sqhk.co/tatidukigag/imShhjd/jukojukijamoroxofawabut.pdf
    • https://cdn.sqhk.co/setuboluraje/urhcdih/naluxi.pdf
    • https://cdn.sqhk.co/mewixamok/iGjbe1T/hd_screen_recorder_video_recorder_app_download.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://73af689e-4c80-4f62-99d3-7a886641ad81.filesusr.com/ugd/3b5dd9_45b671331ee346dbb7cbcc59fa2c5231.pdf?index=true
    • https://e8e87dc5-637d-47ba-9de6-e7d98d123d78.filesusr.com/ugd/a69a03_7b4541a9bdb34c1bb4a37b1e7f0e381f.pdf?index=true
    • http://nulabede.epizy.com/nupererudosip.pdf
    • https://s3.amazonaws.com/wikurixobelu/kamyab_jawan_program_form_filling.pdf
    • https://s3.amazonaws.com/nefomojuwet/ripagenolifinukutelo.pdf
    • http://misiwoferejisuj.rf.gd/reregazizewujisevup.pdf
    • https://972af30b-04c2-4618-b911-83ba0b7fef9e.filesusr.com/ugd/84a5c6_7b4d226e727248dfa06c3cdeadbdbaa5.pdf?index=true
    • http://mawebiruna.rf.gd/92584998293.pdf
    • https://s3.amazonaws.com/kuxegu/dr_heidegger_experiment_discussion_questions.pdf
    • https://s3.amazonaws.com/nolarifaforuxop/amazon_stock_historical_performance.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000edaa.bin
58ffc11a32624f41078dc16990d28d50d3612904069c4985dcfa6312ec097f35
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDAA 5540 bytes
font_01_sfnt_off00010073.bin
24f2833185fa8a63ef19adb0cbb44dfd5add6e6db6ac117197069b3878e709dc
pdf-font-stream PDF embedded font (sfnt) at offset 0x10073 10676 bytes