Malicious PDF — malware analysis report

Static analysis result for SHA-256 9717dd58ca2e8f20…

MALICIOUS

PDF

73.4 KB Created: 2021-03-14 13:31:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5b46a577212764c289abd9572d7b862 SHA-1: 987fcaad52a450a8b9a03478c3e3f61e456415c4 SHA-256: 9717dd58ca2e8f20b1607163913bdd35288b89aabb014c8f22a69d023ba27e30
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating embedded external URIs. The document body, though heavily obfuscated, contains references to 'Egglettes recipes pdf' and 'wkhtmltopdf', suggesting a lure to disguise malicious content. The presence of multiple unknown reputation URLs further supports a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/award?keyword=egglettes+recipes+pdf
    • http://callup.today/bruce_buffer_it_s_time_gif_with_soundqbkgd.pdf
    • http://pagexanomala.22web.org/new_album_song_2019_malayalam.pdf
    • http://detonicinitalia.website/camponotus_ligniperdus_formicariumyjhah.pdf
    • http://umniashka.ru/20574494836umtj7.pdf
    • http://fibutogu.mywebcommunity.org/vopomukixatoruzapekafup.pdf
    • http://xanejog.medianewsonline.com/henry_beston_the_outermost_house.pdf
    • http://medicinfo.online/worst_score_on_family_feud_fast_moneywc281.pdf
    • http://zobabikox.medianewsonline.com/ronunubafuze.pdf
    • http://raxewaponoxiv.mygamesonline.org/aryabhatiya_sanskrit.pdf
    • http://maxobujixeweden.sportsontheweb.net/regigakubedutene.pdf
    • http://unreguezff.rest/determining_the_limiting_reactant_lab_answers8o0tu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gubadif.myartsonline.com/electrical_engineer_salary_jacksonville_florida.pdf
    • http://faleferesevo.onlinewebshop.net/diramokofijanuku.pdf
    • https://s3.amazonaws.com/fedufiporara/15897519780.pdf
    • http://vebusatoro.atwebpages.com/keniritux.pdf
    • https://s3.amazonaws.com/lixuduwonifa/18713899904.pdf
    • http://zilidezokap.epizy.com/apache_cordova_tutorial.pdf
    • http://fujaled.epizy.com/bariwuxoluxaf.pdf
    • https://s3.amazonaws.com/miledu/aloe_blacc_love_is_the_answer_bersetzung.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e380.bin
1f4a6c72d52d622696d0b57c307be51dfff44e0c2faafb8f8daeaf42afc13bbb
pdf-font-stream PDF embedded font (sfnt) at offset 0xE380 5072 bytes
font_01_sfnt_off0000f4e0.bin
3eb3fe517217030d6a81eaab714f2ea2999629af05cf394ad4354c7e4b342a8a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4E0 10684 bytes