Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3d3bf9a36bd9f86…

MALICIOUS

PDF

232.6 KB Created: 2022-06-02 01:49:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3) First seen: 2022-07-15
MD5: 6706850269205ed7eb85aeaa5c28c7c0 SHA-1: 61178fe67eb252e0b84f71f923ee4898db11d1f2 SHA-256: a3d3bf9a36bd9f86580731473e69f9e890d3c84afd221c8e9bddb3eb6c6d9899
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains an embedded URI pointing to a suspicious domain, identified by heuristics as a potential phishing or malware distribution vector. ClamAV detection and ML classification further support its malicious nature. The document body is heavily obfuscated and does not provide clear textual content, but the presence of the external URI is the primary indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9102

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mifuj.co.za/XSRYdR1H?utm_term=the+sims+mobile+guide+marriage++torrent+pc
    • http://www.holzbau-hoelzl.at/wp-content/plugins/formcraft/file-upload/server/content/files/1626609994398a---93791256437.pdf
    • http://uro-medical.pl/zdjecia/fotki/file/gelisigixedivadovo.pdf
    • http://tonyprins.nl/images/uploads/file/jidoxe.pdf
    • https://fosatizifokazu.weebly.com/uploads/1/4/1/6/141675741/c94b925b3dd118.pdf
    • http://vibestedu.com/_UploadFile/Images/file/poboke.pdf
    • https://daporutudinewod.weebly.com/uploads/1/4/1/7/141759445/72734d9ae85.pdf
    • https://diruxopegew.weebly.com/uploads/1/3/4/7/134713863/soxosebo-lalepina-feguwirogu.pdf
    • https://gorumuzupiv.weebly.com/uploads/1/3/4/5/134510920/jovisulenakuxi_dozatidukeragot_ruzakomom.pdf
    • https://xesuxikoju.weebly.com/uploads/1/3/4/0/134095833/aa1360.pdf
    • https://konexogu.weebly.com/uploads/1/4/1/8/141863241/liwuborel-davanavobomipiw-duxefubevarewab.pdf
    • https://bifekanivixu.weebly.com/uploads/1/3/1/4/131408854/ranim.pdf
    • http://kbinteriery.cz/userfiles/file/39323770556.pdf
    • https://zemibojonu.weebly.com/uploads/1/3/5/3/135324970/kanositevetere-romuj-nasiloxedewez-ginudoli.pdf
    • http://avandcie-automation.com/ckfinder/userfiles/files/zofej.pdf
    • https://riguzugekupitov.weebly.com/uploads/1/4/1/5/141557401/2b005.pdf
    • https://marblobath.marblobaths.ph/app/webroot/img/files/37971967384.pdf
    • https://kabasugubofepep.weebly.com/uploads/1/4/1/2/141258413/842431.pdf
    • https://sinijeba.weebly.com/uploads/1/3/5/3/135329812/9514673.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00032fd8.bin
5ad780ea42ff150afc8d34b46c01ede6230fc7f04cffb29af7773d672ed418d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x32FD8 19344 bytes
font_01_sfnt_off00036255.bin
db681b5ebe9430259affd2bc3e467e51337a83b1f4b0bf4f311d9f7a08114ff9
pdf-font-stream PDF embedded font (sfnt) at offset 0x36255 11164 bytes
font_02_sfnt_off00037bd2.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x37BD2 16792 bytes