Malicious PDF — malware analysis report

Static analysis result for SHA-256 a25cc1a69146c33a…

MALICIOUS

PDF

85.2 KB Created: 2021-07-05 06:38:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 329b8a25cb081edad3f45cf4300ebbe7 SHA-1: d78adc486977b50529e72743bead4b92c5723bd1 SHA-256: a25cc1a69146c33adc1cc5acc45dba8356ac443e58a646ef24c5a2dc056b3087
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, specifically those pointing to PDF files on various domains, suggests a phishing or credential harvesting attempt. The PDF_URI heuristic further supports the presence of external links within the document, likely intended to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://insfilings.com/skyzone_classic/upload/files/jilem.pdf
    • https://cytairtool.com/test/userfiles/file/20210705_11523.pdf
    • https://www.mercedesbenzofaustinservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a67675569fd---86823568518.pdf
    • https://www.americanapi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c694b63e34b---tobeviwavodosiguzura.pdf
    • https://soba05.org/wp-content/plugins/super-forms/uploads/php/files/4225742374dd56f90ee05cdaa8c70d04/zavikuniniwipumix.pdf
    • http://adanateknikservis.web.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1607e5a00d447c---18010130166.pdf
    • http://www.thelawchamber.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aba5a67d4ea---25524925554.pdf
    • https://www.sadcmedia.com/wp-content/plugins/super-forms/uploads/php/files/c3mcsqdpq6h3ud2u1ki0992rc7/98458620860.pdf
    • https://www.tifdip.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608b4fe6483d4---juvekuluzosoturanodit.pdf
    • http://veronicanealhome.com/wp-content/plugins/formcraft/file-upload/server/content/files/2/1606f058117432---22678125582.pdf
    • http://volamtuyetthe.com/userfiles/file/jawewawimaparodi.pdf
    • http://sad-azov.ru/wp-content/plugins/super-forms/uploads/php/files/8d78bba3ee2e6e01b9324ae20d689bb2/digudanawafu.pdf
    • http://artmetinc.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607df8470d4ca---44697183746.pdf
    • https://cullinanconstruction.com/wp-content/plugins/super-forms/uploads/php/files/uunldogted5m0obnjgcr6qa1ih/luzukuvibaxoxe.pdf
    • https://rubenferro.com/userfiles/file/nuzurezuk.pdf
    • https://morethancleaningservices.com/wp-content/plugins/super-forms/uploads/php/files/65e4df5e347c6cb9be20816f0cdc90ae/tapositakonuzaxuv.pdf
    • http://griswoldremgmt.com/uploads/files/jadigawoxagu.pdf
    • http://adhdadvisory.com/wp-content/plugins/formcraft/file-upload/server/content/files/16090b9ed2d0e3---82085326672.pdf
    • https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a203c2eed85---41545638513.pdf
    • http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1606c864c54600---89068961471.pdf
    • http://www.iamgoingto1996.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d213f349961---lusaxovebevewofo.pdf
    • http://www.toeterloeh44.de/files/malipofawuvik.pdf
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/YTWXjIUwRh0/uplcv?utm_term=but+it+hurts+so+good+can+you+say+it
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e662.bin
93f5a78c842af2895275d7c81a90d07312cb8750d40a1d2f3f4e4f66568bf4c7
pdf-font-stream PDF embedded font (sfnt) at offset 0xE662 18020 bytes
font_01_sfnt_off0001152c.bin
40ad90ca4f0423610666a0c5beb0519ed8cc614ad743401ced48c3d4efcdc730
pdf-font-stream PDF embedded font (sfnt) at offset 0x1152C 10740 bytes
font_02_sfnt_off00012db1.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12DB1 16792 bytes