Malicious PDF — malware analysis report

Static analysis result for SHA-256 96cce6b26ff0c0ba…

MALICIOUS

PDF

75.6 KB Created: 2021-03-17 06:09:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d2d42bfa9ab34d6bd03cfbdad9417e2b SHA-1: d627f517537512f85938ffd21116a6f0bc2a493f SHA-256: 96cce6b26ff0c0ba6b0de4921ffeaffc3a50a2e765b699298f6e2f76a8fba112
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that masquerades as a search result for security cameras, likely to trick users into visiting a malicious site. ClamAV detection and ML classification strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=best+security+cameras+from+costco
    • http://myfoxing.online/bibodegopururajemucp5v.pdf
    • https://static.s123-cdn-static.com/uploads/4473916/normal_5fddcf7ebb0dc.pdf
    • https://cdn-cms.f-static.net/uploads/4413462/normal_604610240f207.pdf
    • http://suzupuwejal.mygamesonline.org/allen_bradley_rslogix_5000_training_manual.pdf
    • http://nout-prokat.website/cuisinart_tob-260n1_chefs_convection_toaster_oven_stainless_steelvyyar.pdf
    • http://ninomut.sportsontheweb.net/30198366592.pdf
    • https://static.s123-cdn-static.com/uploads/4381102/normal_5fc7582c20f55.pdf
    • http://fajujefa.getenjoyment.net/61470090822.pdf
    • https://static.s123-cdn-static.com/uploads/4453344/normal_5fe472ecd2910.pdf
    • http://fabujisaw.mygamesonline.org/92307763179.pdf
    • https://static.s123-cdn-static.com/uploads/4484156/normal_5fe0eeca2e143.pdf
    • http://pedaxofanor.mywebcommunity.org/dekuwawomit.pdf
    • http://fiziwafofekaku.mygamesonline.org/blends_worksheets_for_kindergarten.pdf
    • http://springital.fun/835854328509h12f.pdf
    • https://cdn-cms.f-static.net/uploads/4499282/normal_601bd19e89c9c.pdf
    • http://xawamiwupajev.mygamesonline.org/84359523421.pdf
    • https://cdn-cms.f-static.net/uploads/4497093/normal_5fda401a52965.pdf
    • http://pugorot.mygamesonline.org/percy_jackson_books_best_to_worst.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/baxegezivumi/80035890119.pdf
    • http://susabumo.atwebpages.com/6731805735.pdf
    • https://s3.amazonaws.com/zozofufulolig/new_malayalam_movies_links.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eaf5.bin
0a03fc7cdb16f654791b0b93c7466862640eeaf4ee474b9d0b6c4f5060433c63
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAF5 5144 bytes
font_01_sfnt_off0000fc6f.bin
6327cc57b72690957b63b6b6a8ca4fef455af3b778776a39234796187e748e67
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC6F 10720 bytes