Malicious PDF — malware analysis report

Static analysis result for SHA-256 a63f8f65192eca46…

MALICIOUS

PDF

104.6 KB Created: 2021-04-20 13:01:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 7c4fe0743045f861116dafba9b4f41f8 SHA-1: 20437b2923c8d8ed05821ef911c2df28ea2b3382 SHA-256: a63f8f65192eca46d6d45681b498c71d5628cc203d4b33961d53e95d6e951dff
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded external URI pointing to a suspicious domain, identified by heuristics as a potential phishing or malware distribution lure. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URL suggest it's designed to redirect users to a malicious site, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9978

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=p%2526id+symbol+library+autocad+free PDF link annotation
    • https://cdn.sqhk.co/mitejapeki/icugiXT/final_fantasy_record_keeper_tier_list.pdfIn PDF document text
    • http://zonitupupafof.sportsontheweb.net/pikerogikuxi.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4462093/normal_60132b7cb016b.pdfIn PDF document text
    • http://momarivido.mypressonline.com/como_cambiar_el_formato_de_fecha_en_excel_dia_mes_ao.pdfIn PDF document text
    • http://paxezimusosesa.scienceontheweb.net/antenna_theory_balanis_book.pdfIn PDF document text
    • http://jamotovoxut.mywebcommunity.org/abstract_verbal_reasoning_skills.pdfIn PDF document text
    • https://cdn.sqhk.co/votawusebak/gdhejd6/gunipewuvezalexujitid.pdfIn PDF document text
    • http://peromopativej.mypressonline.com/ibm_selectric_typewriter_original_price.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454281/normal_5fd6d22b4fef4.pdfIn PDF document text
    • http://masovizifuzaro.iblogger.org/julewe.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393486/normal_5fd99e9674211.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4474734/normal_6002e288ac115.pdfIn PDF document text
    • https://cdn.sqhk.co/difixoruze/ijgKhcS/sabuvitasa.pdfIn PDF document text
    • http://vebofituzor.iblogger.org/37048006064.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375521/normal_605559cf03bea.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://s3.amazonaws.com/rorives/maven_setup_eclipse_project.pdfIn PDF document text
    • https://s3.amazonaws.com/tupofelasujewas/katej.pdfIn PDF document text
    • https://s3.amazonaws.com/nowokil/42695326358.pdfIn PDF document text
    • https://s3.amazonaws.com/navoburarovada/belatowebiruxawonuzoved.pdfIn PDF document text
    • http://rodukamofuf.epizy.com/unsw_kensington_map.pdfIn PDF document text
    • https://s3.amazonaws.com/xazarujokemus/wirusagavo.pdfIn PDF document text
    • http://dozodikud.epizy.com/53845263065.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off00016723.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x16723 19964 bytes
SHA-256: 00f200563c522938cef449da520e4ffa7a505df6a0e5706741d2e7b41212bd68
font_00_sfnt_off0000efb7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEFB7 7712 bytes
SHA-256: 8888faa770cd16027d7bf5a5033ba78b96921d07e4516f30f94383cd69b78242
font_01_sfnt_off00010a00.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A00 4156 bytes
SHA-256: f98b29c861490552b8a4d6ceea70da7e1565e5f7db010c3d40d3b520861c1511
font_02_sfnt_off0001181e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1181E 9752 bytes
SHA-256: 49915b76fc8665086d32c786612a0298c9b1c44e0912ada55a151813a5fc710e
font_03_sfnt_off000133a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x133A8 16792 bytes
SHA-256: 4e49331385b5bcdc47d808c82fbe6154026e2caeb2411a90f20855fa0dfaa1a3
font_05_sfnt_off00018756.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18756 3280 bytes
SHA-256: 9f373969545e9f7dd9480b192e2ff71060746c8ff9a18817a0acbed9c7f3568d