Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b61aa926c991d61…

MALICIOUS

PDF

74.6 KB Created: 2021-03-18 14:34:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4357c44bcfba0906764c589d2628f525 SHA-1: 2fdbe704e941964ecfad7474298fa920ca19d96d SHA-256: 9b61aa926c991d6103d8a84000f8b02b13a6d1900d571680c8ee90124f8fbb06
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with a high risk score. It contains an external URI pointing to a suspicious domain, likely intended for phishing or malware distribution. The document body, though heavily obfuscated, suggests a lure related to educational worksheets, aligning with a spearphishing attachment tactic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/award?keyword=addition+worksheets+2nd+grade+pdf
    • https://static.s123-cdn-static.com/uploads/4366015/normal_5fcad3c337608.pdf
    • http://ginupedarokuxu.getenjoyment.net/59613543449.pdf
    • https://cdn-cms.f-static.net/uploads/4490739/normal_603e8e5ce1db9.pdf
    • http://neridofufuleteg.scienceontheweb.net/best_java_books_for_beginners.pdf
    • http://kukogekaw.sportsontheweb.net/66646219968.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dukajevo/jutaren.pdf
    • https://s3.amazonaws.com/benuka/86944364316.pdf
    • http://zitasixan.atwebpages.com/twilight_breaking_dawn_part_2_soundtrack_cd.pdf
    • https://s3.amazonaws.com/mubemutolewe/89175866169.pdf
    • https://s3.amazonaws.com/fuzafuzeruwit/pulmonary_hypertension_canada_guidelines.pdf
    • https://s3.amazonaws.com/bofake/properties_of_alcohols_and_phenols_lab_report.pdf
    • https://s3.amazonaws.com/zevutebulaworel/1206068835.pdf
    • https://s3.amazonaws.com/degisapemifa/english_comprehension_passages_questions_answers.pdf
    • https://s3.amazonaws.com/mogipegi/lutapolagoriku.pdf
    • https://s3.amazonaws.com/tosevud/old_mans_war_movie_trailer.pdf
    • https://s3.amazonaws.com/woxorojero/tibutajulalup.pdf
    • https://uploads.strikinglycdn.com/files/1d7b09c4-e71a-41e9-a5a6-a53a0d6114a7/49682782851.pdf
    • https://s3.amazonaws.com/labitajaxatufib/latest_book_and_author_name_2018.pdf
    • https://s3.amazonaws.com/rovikibixu/girl_scout_law_coloring_sheets.pdf
    • https://s3.amazonaws.com/benubapopikaj/hotstar_app_apk_new_version_2019.pdf
    • http://belibivizonojo.myartsonline.com/sijabajuli.pdf
    • https://s3.amazonaws.com/tinezedu/annexure_3_of_nps_form.pdf
    • https://s3.amazonaws.com/sizabo/contractions_worksheet_1st_grade_free.pdf
    • https://uploads.strikinglycdn.com/files/9e4661a7-a11c-4c85-b1d5-b8912c311b7d/how_many_calories_in_a_arbys_half_pound_roast_beef_sandwich.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e420.bin
8b1e5724852e5e67f22e70b4b2631a5ec983d7f7335806bb0ce0cbcde4045cec
pdf-font-stream PDF embedded font (sfnt) at offset 0xE420 5548 bytes
font_01_sfnt_off0000f715.bin
eb07e2d70139f5d8ebccd3845499e95d42042d4e7cd7b683da5e19a32822fdc1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF715 11224 bytes