Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6fd4f669af5e83a…

MALICIOUS

PDF

76.2 KB Created: 2021-04-30 15:57:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 1bc47d36cbbb7a6f2bde8e9643f66d7d SHA-1: e1884b8ac0cc7fe5017eb84d3dbb98a19a7a513c SHA-256: a6fd4f669af5e83a12d96fa6d2f204280882645a38e48c30a548f33765fb8248
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/strik?utm_term=quicksilver+throttle+control+models PDF link annotation
    • http://limons.space/upenn_face_masks_for_salepptob.pdfIn PDF document text
    • http://mofonuf.medianewsonline.com/zumevujogevikigewifalife.pdfIn PDF document text
    • http://help-feedback-amzn6.xyz/bu_college_admission_form_201971u1x.pdfIn PDF document text
    • http://tujidal.mypressonline.com/cuantos_son_los_libros_juego_de_tronos.pdfIn PDF document text
    • http://sutezesibopixiv.medianewsonline.com/nexatasirobowopimaxuneb.pdfIn PDF document text
    • http://wivaserana.mywebcommunity.org/describe_some_social_problems_of_vulnerable_populations.pdfIn PDF document text
    • http://gopidap.scienceontheweb.net/ventilator_associated_pneumonia_adalah.pdfIn PDF document text
    • http://bewewafip.scienceontheweb.net/neato_botvac_d401_connected_-_saugroboter.pdfIn PDF document text
    • http://pofuxubilet.sportsontheweb.net/49504386397.pdfIn PDF document text
    • http://xijivedijimidip.mygamesonline.org/bsc_agriculture_colleges_in_karnataka_download.pdfIn PDF document text
    • http://lusaxesa.iblogger.org/26387843035.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://sesosufavi.epizy.com/44437082074.pdfIn PDF document text
    • http://xezaretidatoro.onlinewebshop.net/attestazione_di_conformit_catastale.pdfIn PDF document text
    • http://pivotigapux.rf.gd/rofat.pdfIn PDF document text
    • https://s3.amazonaws.com/rutufokedizon/5540284208.pdfIn PDF document text
    • https://s3.amazonaws.com/kovozenamofox/what_questions_to_ask_when_buying_a_small_business.pdfIn PDF document text
    • http://pakuzubexur.rf.gd/iata_icao_airport_codes_list.pdfIn PDF document text
    • https://s3.amazonaws.com/jozetej/cengage_chemistry.pdfIn PDF document text
    • https://s3.amazonaws.com/neviwove/koputamezajerulukuro.pdfIn PDF document text
    • https://s3.amazonaws.com/rorives/video_chucky_5_full_movie.pdfIn PDF document text
    • http://bukadalisurofez.epizy.com/fuelseurope_statistical_report_2019.pdfIn PDF document text
    • https://s3.amazonaws.com/sifawekujiki/find_the_length_of_arc_ab_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/mokuwanibof/wufirufitafezipene.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec07.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC07 5152 bytes
SHA-256: 46e129bac3aefa44cddc10053468cfb95a8a55edd7791fd078ba92c67ab3f91c
font_01_sfnt_off0000fd6f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFD6F 10616 bytes
SHA-256: 8cadbf1b6cdd01d98247811ca5ae700797b2f71514d42d99ed8cc9d71f109ecc