Malicious PDF — malware analysis report

Static analysis result for SHA-256 9cd10fd75bb8f1c7…

MALICIOUS

PDF

68.5 KB Created: 2021-05-13 01:55:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e2f9a6d68db38d41339a41d9bc9e3139 SHA-1: 894c309f732d130c17e60a3f374fe26d62bc8588 SHA-256: 9cd10fd75bb8f1c7685c86af5a30cf93602c842f3836651055b2b7002a11c9ea
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains embedded URLs, one of which points to a suspicious PDF file hosted on a compromised-looking WordPress site. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to malicious content, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://portsidestrategies.com/wp-content/plugins/super-forms/uploads/php/files/c5414a8934822ac845c0afe44601da8d/sokirid.pdf
    • http://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/16087ef8f9efdc---71624865754.pdf
    • https://celovechurch.org/wp-content/plugins/super-forms/uploads/php/files/4a966ca8929d8854b9304c2d666bab4e/negunulixebaxat.pdf
    • https://bursaceviritercume.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070aa923474d---67133790770.pdf
    • https://almondzwealth.com/administrator/imagetemp/file/1836414044.pdf
    • http://angelojrobles.com/admin_initial_test/userfiles/file/sugadujovajovopisifaw.pdf
    • https://puertoestereo.com/wp-content/plugins/super-forms/uploads/php/files/lpt0b5rv9jcujsdfpa7dkhrr17/33987116041.pdf
    • http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607f8933dfcd2---migigokuxirijam.pdf
    • http://www.victorian-manor.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/16075e8bd7972a---67077790151.pdf
    • https://cruiseship.cruises/wp-content/plugins/super-forms/uploads/php/files/isamlns7u32qsdehdi2m8pulqm/golikavopaf.pdf
    • https://www.emmabowman.com/wp-content/plugins/super-forms/uploads/php/files/5b768263fc4df270aee1b515f99d9a5e/35883716902.pdf
    • https://miamiuniquelimo.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ce2207e0a4---15441317433.pdf
    • https://nhaban24h.com.vn/wp-content/plugins/super-forms/uploads/php/files/3e70vppe7kmjm6kv0s4rn0ggs6/xisujofita.pdf
    • https://sharzh-ufa.ru/wp-content/plugins/super-forms/uploads/php/files/13532309d2a1d7d5fdb8761afe077cfe/55259538016.pdf
    • http://www.thelawchamber.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608d8c50be970---fosekelojarovisosode.pdf
    • https://www.dishdivvy.com/wp-content/plugins/super-forms/uploads/php/files/6510002093759560708e36e4f6e672a5/jawejexarafep.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/3CAf4wW3hvY/uplcv?utm_term=writing+equivalent+fractions+worksheet
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cead.bin
6ac19502af707700dd01de99a67f1ef2b2782fd10994fa6d9318821c9d9afd81
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEAD 5500 bytes
font_01_sfnt_off0000e180.bin
16bb492f2f4e21cc970d079e38ed5ea2560ac386ab9ffaf6aeb6333de5d33a4c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE180 10404 bytes