Malicious PDF — malware analysis report

Static analysis result for SHA-256 95998237460aa859…

MALICIOUS

PDF

96.2 KB Created: 2021-03-27 10:23:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dbbdfc393b66df3adad9da82d48f457f SHA-1: 3a2138520c0b9a8c5c9e670baebb1c65cdd3568f SHA-256: 95998237460aa859bd7e6b8e5b7e4a81bcdad9fb988cf89ca6eb1d3783cb21eb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. The embedded URL and numerous other URLs suggest a phishing or malware distribution attempt. Although no scripts were explicitly extracted, the PDF structure and external URL firings indicate it's designed to redirect users to malicious sites, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=unity+day+2016+download
    • https://cdn.sqhk.co/baruduwege/dFidXgg/angry_birds_space_apk_mod.pdf
    • http://kind-insta.site/dagaltj2hj.pdf
    • http://table-wait.com/introduo__teoria_geral_da_administrao_idalberto_chiavenato_download2vk62.pdf
    • https://static.s123-cdn-static.com/uploads/4464067/normal_5fceab49950c5.pdf
    • https://cdn.sqhk.co/rajunakeb/MN0jigc/63607813506.pdf
    • http://stingeksoj.online/chronotherm_iv_plus_manualrqma9.pdf
    • http://rbqjkwklnd.xyz/easy_pencil_drawing_of_flowers6xij3.pdf
    • http://saleproducts.pro/28403193985h3lj6.pdf
    • https://cdn.sqhk.co/busanurutar/QnhjdCl/word_life_crossword_puzzle_mod_apk.pdf
    • https://cdn.sqhk.co/tusadopovet/6jdJicT/amhara_population_2017.pdf
    • http://getallcreditscores.info/how_to_do_fundamental_and_technical_analysis_of_stockslubxh.pdf
    • http://aicberg.net/piwatevupatalurodefaweksadq.pdf
    • https://cdn-cms.f-static.net/uploads/4384820/normal_5fd644cd5837e.pdf
    • http://mybestchan.online/jasemifrx4ok.pdf
    • http://wezenilokiwuv.iblogger.org/rented_house_inventory_template.pdf
    • https://cdn.sqhk.co/xejudawadoni/hdzhcjh/boom_beach_mech_troop_levels.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://pomewegipezu.rf.gd/sutalazavisinel.pdf
    • http://fexonawu.epizy.com/ligisedonetimujata.pdf
    • http://bofutezexo.rf.gd/accumulator_function_in_hydraulic_system.pdf
    • http://fanevisexika.epizy.com/37364507789.pdf
    • http://difadedox.rf.gd/accreditation_letter_format_for_college.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013a6d.bin
a73d3abb79ed232dfd5d2bf0ef3f5a3e148007f6c3d1ac0c98bafabc4a195673
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A6D 5208 bytes
font_01_sfnt_off00014c58.bin
81a9a5bc3e817c1676e079efe03f348b12862569b0faa739442fa73fc8e479d9
pdf-font-stream PDF embedded font (sfnt) at offset 0x14C58 11168 bytes