Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d0be43407a37935…

MALICIOUS

PDF

62.7 KB Created: 2021-04-02 17:30:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 05920149541d3bb3fadfbd604d260dac SHA-1: 0edee833eafbe184930f7d89fff8f963f3f0ed39 SHA-256: 9d0be43407a3793555de0978c5e26be8f635e3aa60a2e923ff750b4e2bd8030e
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, identified as malicious by ClamAV and ML classifiers. The document body, though heavily obfuscated, suggests a lure related to programming resources to entice users to click the malicious link. No scripts were extracted, but the presence of the malicious URI and the heuristic firings strongly indicate a phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8313

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/award?keyword=introduction+of+c+programming+pdf
    • http://gediputelilana.22web.org/kewefebajixeg.pdf
    • https://cdn-cms.f-static.net/uploads/4460255/normal_602d5aaa010e1.pdf
    • http://detonic-romania.website/binitolibidabogawog4k1bh.pdf
    • https://static.s123-cdn-static.com/uploads/4365599/normal_5feced34e8327.pdf
    • https://cdn-cms.f-static.net/uploads/4451556/normal_602c0a79e51da.pdf
    • https://static.s123-cdn-static.com/uploads/4369317/normal_5fde29af1fcb5.pdf
    • http://doctora.club/square_root_chart_1_100rjddt.pdf
    • http://mnclassis.org/how_to_build_a_dog_house_easy_and_cheap4mtqq.pdf
    • http://shishkin-seed.xyz/how_to_change_user_codes_-_schlage_connect_smart_deadboltesbzj.pdf
    • http://govnosiakxws.online/93782272839rqzf6.pdf
    • http://vurapajojijare.22web.org/dot_plots_and_histograms_practice_worksheet.pdf
    • https://static.s123-cdn-static.com/uploads/4465559/normal_600808a9816fb.pdf
    • http://gekidomemurij.iblogger.org/jurubapijuforalumoduvedij.pdf
    • http://vavoferidedodif.66ghz.com/avatar_full_movie_hd_telugu.pdf
    • http://xuribof.medianewsonline.com/jacques_bainville_petite_histoire_de_france.pdf
    • http://mojenisijita.mywebcommunity.org/xebatexorewet.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/rirusozo/62297541666.pdf
    • http://rarazimefuv.rf.gd/relion_wrist_blood_pressure_monitor_error_codes.pdf
    • http://mapelapelebiben.rf.gd/nuzas.pdf
    • http://kobaporosonunaw.rf.gd/53354055323.pdf
    • https://s3.amazonaws.com/xakajoziwibi/nc_appellate_style_guide.pdf
    • http://totuxivez.onlinewebshop.net/how_much_weight_is_3000_calories.pdf
    • http://keregimuw.onlinewebshop.net/femededepodo.pdf
    • https://s3.amazonaws.com/tiniruru/nemuxebaxa.pdf
    • http://bozudob.epizy.com/mayflash_f300_template.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9f3.bin
8b8d3d7e5e8c037512c72a7554c01f18f910cd94ff1fd812359afe083a35b8e9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9F3 5204 bytes