Malicious PDF — malware analysis report

Static analysis result for SHA-256 995018fb6dac555d…

MALICIOUS

PDF

70.3 KB Created: 2020-12-15 04:16:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b9c61e7d38866bd8481451ccd0c3f92c SHA-1: d2099dc50fb0fa846857c2b1580a71b77328720f SHA-256: 995018fb6dac555dae27a21644e6d5ef7eeb9626d58a7636d04b7f25f8c426a6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains an embedded URL pointing to a suspicious domain, which is a common tactic for phishing lures or malware distribution. Although no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest an attempt to redirect the user to a malicious resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=einthusan+music+video+er
    • https://cdn-cms.f-static.net/uploads/4405946/normal_5f9cd108e387c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2f26e90a-c645-4368-8ba6-977ee744a9b6/bobomanekutamapagejoje.pdf
    • https://static1.squarespace.com/static/5fc0f08c104edf1d7780fb42/t/5fccb982662d5e24e09f0deb/1607252354939/92745926291.pdf
    • https://s3.amazonaws.com/numunenoji/movies_to_phone.pdf
    • https://static1.squarespace.com/static/5fc0d4c78139af037644e8c4/t/5fc94e6359093a79be192636/1607028323689/auto_followers_for_twitter_free.pdf
    • https://uploads.strikinglycdn.com/files/f46d1d77-3d0c-4df9-8218-4aac93a035ee/soxegejusel.pdf
    • https://uploads.strikinglycdn.com/files/39b56573-addf-419c-9ed4-f7b107eb1796/pufuvumibuxunakafof.pdf
    • https://uploads.strikinglycdn.com/files/6b1e8385-4e81-415c-b0bb-a3bd6c16df28/onkyo_skf-4800_speakers_review.pdf
    • https://uploads.strikinglycdn.com/files/23541297-59fa-426c-94f7-2f7387e48396/bozeman_biology_photosynthesis_and_respiration_video_answers.pdf
    • https://uploads.strikinglycdn.com/files/42f8c7e4-b8dc-4df9-97ff-58a9a329cc67/92196615503.pdf
    • https://uploads.strikinglycdn.com/files/db8f629a-84d2-4275-964b-127763489fd9/the_4-hour_work_week_full_book_free_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d550.bin
9ff2e5226b035b412a52e6081d1705ed90cc33e4100105df2ada6ac06b918b55
pdf-font-stream PDF embedded font (sfnt) at offset 0xD550 5164 bytes
font_01_sfnt_off0000e6bb.bin
69defcd66020f86a079a9e3bde3ee5224fa43a6e60d618c9add7eff995358a84
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6BB 11612 bytes