Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2983086f046c53f…

MALICIOUS

PDF

77.1 KB Created: 2021-03-07 09:09:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2e75c81fd9f80fe3253af0c347aa018f SHA-1: 23e63236c3d2487da6ce59404283dccf7ead8d7c SHA-256: a2983086f046c53f7267647459fa9e1c102816ff8f322e0c3f5dbbf6f62108b6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, indicating an attempt to redirect the user to a malicious site. The ML classifier and ClamAV detection strongly suggest malicious intent, likely for phishing or malware delivery. While no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a common attack pattern for distributing malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/aws?utm_term=microsoft+word+keyboard+shortcuts+copy+paste
    • https://jomefexud.weebly.com/uploads/1/3/4/7/134732593/jizasizenuwijat.pdf
    • https://static.s123-cdn-static.com/uploads/4420438/normal_60005310ed60e.pdf
    • https://cdn.sqhk.co/kasesiseb/bfibchi/91691782334.pdf
    • http://lobulezinovux.medianewsonline.com/how_to_reset_westinghouse_tv_without_password.pdf
    • https://dajolulozofupo.weebly.com/uploads/1/3/4/6/134634221/kolubutetazogil.pdf
    • https://tafifomoku.weebly.com/uploads/1/3/1/8/131856516/966879.pdf
    • https://cdn-cms.f-static.net/uploads/4418199/normal_601d5143dc409.pdf
    • http://nikibolerobika.getenjoyment.net/balewugisibolomen.pdf
    • http://erethiztzj.space/camera_translator_app_apk1tgk0.pdf
    • https://cdn.sqhk.co/jotenitix/hbNMjih/75276359225.pdf
    • http://nicepics.xyz/vitamin_d_deficiency_in_adults_results_inb38j1.pdf
    • https://cdn.sqhk.co/nepajenine/g7jdhek/3695999415.pdf
    • https://cdn-cms.f-static.net/uploads/4462985/normal_602194caacb0e.pdf
    • https://cdn-cms.f-static.net/uploads/4486344/normal_6028195217508.pdf
    • http://delaem-sami.online/ley_de_propiedad_de_condominios_cdmxima63.pdf
    • https://cdn.sqhk.co/gapalagabig/KRggRNB/watuvupe.pdf
    • http://rubewox.sportsontheweb.net/55330879257.pdf
    • http://busforpay.online/axis_cgi_mjpg_motion_jpeguxkvl.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/0363bb4a-7057-42da-9134-ccc5faeb8023/livuko.pdf
    • https://uploads.strikinglycdn.com/files/9f12ef8d-43e7-40c2-81d6-e2d0bb25a73b/72437152484.pdf
    • http://lewinozed.atwebpages.com/lejugoxovifim.pdf
    • https://uploads.strikinglycdn.com/files/537be8bf-b85a-4850-9521-6ec96c0c4781/13963037559.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000edd8.bin
42d8e7ad4103532eff93a80babb3e367007d09737ccf9eff9ced6160d9115c8d
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDD8 5616 bytes
font_01_sfnt_off00010110.bin
d053793a0339bcce141ff553d92a0f0bb45db73993c5d7b99542fee5ddcf358b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10110 11016 bytes