Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a0cfaa46a4e4529…

MALICIOUS

PDF

90.4 KB Created: 2021-02-27 20:45:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1ad898734966e54d6fdc5f0bb7b7e614 SHA-1: 7a8ad3bba68e65131acb308930e657d32fc4c5f8 SHA-256: 9a0cfaa46a4e45293579b89bda833696656472eef7450f27db8ded5afe308bfc
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected by ClamAV as Pdf.Phishing.Trojan and flagged by an ML classifier, indicating malicious intent. The embedded URL and numerous other URLs point to suspicious domains, likely serving phishing content or malware. The heuristic 'SE_URGENCY_LURE' suggests the document attempts to create a false sense of urgency to prompt user interaction.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/wix?keyword=vampire+academy+pdf+weebly
    • https://cdn.sqhk.co/doxufojixene/cfhg2U9/73313577721.pdf
    • https://cdn.sqhk.co/wazofovam/MiahjGm/where_to_get_my_nails_done_near_me.pdf
    • https://cdn.sqhk.co/tizesefetus/CjaFoPl/wuxavikixetenadunobiv.pdf
    • https://cdn.sqhk.co/wosipuvetot/idMhgaK/49167569366.pdf
    • https://cdn.sqhk.co/rorajakura/hczxWgc/pekipewomelewogaroxot.pdf
    • https://cdn.sqhk.co/xenojepezere/5mnihKE/5_celestial_bodies_in_our_solar_system.pdf
    • http://sugameloxufe.mywebcommunity.org/the_film_experience_5th_edition_audiobook.pdf
    • http://xojuxelase.medianewsonline.com/87037839253.pdf
    • http://xedeporib.medianewsonline.com/brookstone_wireless_speaker_recall.pdf
    • https://cdn.sqhk.co/bitaxukezor/eCzjdhf/wrrc_world_retro_racing_challenge_2020.pdf
    • https://cdn.sqhk.co/jemitaso/9hjL5Q6/tofezuta.pdf
    • https://cdn.sqhk.co/xawefigi/ihhaias/16797735429.pdf
    • https://cdn.sqhk.co/kewukapugino/ihURii8/best_caption_for_facebook_profile_picture_in_nepali.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://nekipusixewid.epizy.com/34262236074.pdf
    • http://relisedozoru.epizy.com/fonopo.pdf
    • http://vevubajiziju.epizy.com/lipijidakuzi.pdf
    • https://s3.amazonaws.com/juduk/bharti_axa_life_insurance_cdf_form.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011910.bin
eecb29039abd04655ad29e49646f40378416461c8db0304b0fb3dde35f937460
pdf-font-stream PDF embedded font (sfnt) at offset 0x11910 4916 bytes
font_01_sfnt_off000129d4.bin
648a93382d68743fd10f43d846217c7fb324873eb7f48ddc8e69166736972f58
pdf-font-stream PDF embedded font (sfnt) at offset 0x129D4 10572 bytes
font_02_sfnt_off00014df8.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x14DF8 4324 bytes