Malicious PDF — malware analysis report

Static analysis result for SHA-256 9872aa98a2c6451e…

MALICIOUS

PDF

75.7 KB Created: 2021-04-17 19:08:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 85ff6c7ea40d440efa41c941fa067dd4 SHA-1: 5085e947de06775cd4089fca83bd896dcdca4d64 SHA-256: 9872aa98a2c6451eef903d187f5859050dd3a3775d78440ea8bb0b42c08a7587
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a phishing or malware distribution site. Although no scripts were explicitly extracted, the presence of embedded URLs and the nature of the detection suggest the document is designed to exploit users through deceptive content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=que+hace+un+lider+con+su+equipo
    • https://cdn-cms.f-static.net/uploads/4456128/normal_60190ba3b01cf.pdf
    • http://instapriz365.online/six_of_crows_2_espaol3hog3.pdf
    • https://static.s123-cdn-static.com/uploads/4421466/normal_5fccf73740e9a.pdf
    • https://cdn-cms.f-static.net/uploads/4446491/normal_60655b6784235.pdf
    • http://masito.space/335990272875j5m.pdf
    • https://cdn-cms.f-static.net/uploads/4445890/normal_5fd628ec373b0.pdf
    • http://supportcopyright.net/how_to_invest_in_stock_beginners6wmxr.pdf
    • https://cdn-cms.f-static.net/uploads/4404488/normal_602d8b250a41e.pdf
    • https://cdn-cms.f-static.net/uploads/4387933/normal_605196cc1747e.pdf
    • https://cdn-cms.f-static.net/uploads/4401703/normal_6060c9498e8f9.pdf
    • http://graatorama.space/20235698075jcvnf.pdf
    • https://cdn-cms.f-static.net/uploads/4414866/normal_60270207c032e.pdf
    • http://copyrightmediahelp.com/the_killing_of_uncle_sam_wikipedia26t0i.pdf
    • https://cdn-cms.f-static.net/uploads/4460694/normal_5fd739a52fb25.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2dcd93aa-70f4-4d99-9f8e-b9c394d25a94/falerolajozep.pdf
    • https://s3.amazonaws.com/nabifovu/39548818844.pdf
    • https://s3.amazonaws.com/pogolo/yamaha_rx_v673_price_in_india.pdf
    • https://uploads.strikinglycdn.com/files/6a83a16d-83c6-4811-917c-24c28ff1c946/una_vida_con_proposito_resumen.pdf
    • https://s3.amazonaws.com/wonumafubij/lamamo.pdf
    • https://s3.amazonaws.com/lizuseguwix/bitibeviligonoluve.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9e6.bin
ff2769d799083bbacbdab7e7f130d05cd900f1a9911f299650add392dfa79f35
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9E6 5348 bytes
font_01_sfnt_off0000fc04.bin
41a7da29a9f30f093ea5e72a3f212b3a9755e83e5e7361d6553abad18234f481
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC04 11220 bytes