Malicious PDF — malware analysis report

Static analysis result for SHA-256 a07e8d8f27a2a152…

MALICIOUS

PDF

123.6 KB Created: 2021-02-23 13:42:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: 86647938bb06317d3b457be876deb605 SHA-1: cf903eeea7ccd78f16df4364fad7f9aa4251e49d SHA-256: a07e8d8f27a2a152ce0e66fe93e0d120d0ed659a7f8b360fde05232c1dc92fdd
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file is a PDF that contains a lure to download a tutorial, which is a common tactic for phishing or malware delivery. The 'SE_ENABLE_LURE' heuristic confirms the document instructs the user to enable macros or editing. ClamAV detection and ML classification strongly indicate malicious intent. The embedded URL is likely the initial point of contact for downloading a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=vba+in+excel+2007+tutorial+pdf+download PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4384167/normal_6016c36987195.pdfIn PDF document text
    • https://cdn.sqhk.co/xasakeza/icwhbgc/mofepuzagunad.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370996/normal_602873d8908b0.pdfIn PDF document text
    • http://tiktokfrance.fun/38633284847et6uc.pdfIn PDF document text
    • https://cdn.sqhk.co/xofozomuwef/sETgfih/bavaromo.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4457332/normal_5ff05ce1a1e9a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4366961/normal_5fcb49bf80673.pdfIn PDF document text
    • https://cdn.sqhk.co/jiguluzufuwa/gchajht/beduboveka.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/luramamelolem/robukimumikujef.pdfIn PDF document text
    • https://s3.amazonaws.com/safenalavojuwu/bijosizubunaxudewatu.pdfIn PDF document text
    • https://s3.amazonaws.com/tuzakifezara/unreported_concussion_in_high_school_football_players.pdfIn PDF document text
    • https://s3.amazonaws.com/liwafo/nccn_guidelines_locally_advanced_pancreatic_cancer.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000199fb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x199FB 5472 bytes
SHA-256: 394acb13d83bb6b41b138ca8db2fd466bd3b8ad282912d873be06034e7cc6b8b
font_01_sfnt_off0001acb9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1ACB9 11184 bytes
SHA-256: 20e83308d7b24e054a6f38bcb67594d86ac30f47e4b0b024621bdac8fe14d032
font_02_sfnt_off0001d305.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D305 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3