Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f4cb6fc37d7967a…

MALICIOUS

PDF

78.1 KB Created: 2021-04-14 12:40:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 38f0dd5354aaa477e6fce03a013ed6e4 SHA-1: 6e6c17a8d18eb2c60899f84272d9d4e658907277 SHA-256: 9f4cb6fc37d7967af852986859ad8c95a283aa684c16ea9540f48e993b72f1d8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is a strong indicator of phishing or malware distribution. The ML classifier and ClamAV detection further support its malicious nature. While no scripts were explicitly extracted, the presence of external URIs suggests an attempt to redirect the user to a malicious site, likely for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=night+shift+police+movie+2020
    • https://cdn.sqhk.co/fusojafiza/jeAhegf/56805679195.pdf
    • https://cdn.sqhk.co/soxosovave/hfiemhc/extreme_landings_apk_android.pdf
    • https://cdn.sqhk.co/takakakod/gdigOha/koloxa.pdf
    • https://cdn.sqhk.co/letarezetap/gchdjaG/lolegafofapolad.pdf
    • https://cdn.sqhk.co/zetikitor/aiavxuy/94203723453.pdf
    • https://cdn.sqhk.co/sirepajaku/iggQchh/givatotadodunegifamebot.pdf
    • https://cdn.sqhk.co/sevafeluba/hckKP8x/aww_pobrecito_translation.pdf
    • https://cdn.sqhk.co/vatojuwa/jLiihbC/52912194380.pdf
    • https://cdn.sqhk.co/tazifawixax/b5bu5vJ/fisiga.pdf
    • http://fogarapisow.22web.org/broderbund_printmaster_free.pdf
    • https://cdn.sqhk.co/fogibadeku/EjfijkG/95370040022.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://livukuxuperum.epizy.com/backless_short_formal_dresses.pdf
    • http://donafilozevore.rf.gd/rawusumim.pdf
    • https://uploads.strikinglycdn.com/files/0455b43c-5162-4380-87b4-4fdf3f4784bb/sopagodeliramizupopepop.pdf
    • http://bitesokilok.epizy.com/brocade_6505_manual.pdf
    • http://tibogav.rf.gd/does_sonic_serve_fried_oreos.pdf
    • http://xajetizefo.rf.gd/85782524566.pdf
    • http://dixadenidufudu.epizy.com/mind_map_template_psd.pdf
    • https://uploads.strikinglycdn.com/files/db88ed26-c5ad-4ff6-b16a-92c2302c2886/where_are_wave_hot_tubs_made.pdf
    • http://xivoxek.epizy.com/75261020186.pdf
    • https://uploads.strikinglycdn.com/files/17d4d3df-fa68-4481-9c4c-cbf51dcb04fb/what_percentage_of_us_steel_is_imported.pdf
    • https://uploads.strikinglycdn.com/files/191071ae-a9c2-4198-98f2-7c32a52e35c8/sepapug.pdf
    • http://vogumogut.epizy.com/addition_and_subtraction_of_fractions_word_problems.pdf
    • http://fewetero.epizy.com/canal_boat_magazine.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f4bc.bin
fd81656aeaf8ec15f31cf59b870a3ee7e2f0882ebb452e23d71eb8033e9c037b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4BC 5424 bytes
font_01_sfnt_off00010737.bin
d5f308cc1c9322447ca78f68f6e89972363f17e6e39a09d78113b2d4c75fa012
pdf-font-stream PDF embedded font (sfnt) at offset 0x10737 10472 bytes