Malicious PDF — malware analysis report

Static analysis result for SHA-256 a829173468c36b7b…

MALICIOUS

PDF

66.5 KB Created: 2021-04-13 19:53:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d8e55a61ac5294fc379699f8633dd042 SHA-1: d85ebc8c4c17266be50159071914cb7f6ce3dc73 SHA-256: a829173468c36b7becae7d32b420ab2049bb615351e01bcbbc22bde252622595
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, specifically one flagged as PDF_URI, suggests an attempt to redirect the user to external sites. Although no scripts were explicitly extracted, the PDF structure and embedded URLs point towards a phishing or malware distribution vector, likely initiated via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8307

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.friendlycc.com/sites/default/files/webform/topevonizudurazot.pdf
    • https://www.mainephilanthropy.org/sites/default/files/lipedoketuparukol.pdf
    • https://www.mainephilanthropy.org/sites/default/files/30695142459.pdf
    • https://www.osgeurope.com/sites/osg-corporate.dev/files/webform/10654010608.pdf
    • http://www.pbttphtk.gov.my/sites/default/files/webform/42283273604.pdf
    • https://www.uts.cw/sites/default/files/webform/dupoxemijuwavamuvugorudiz.pdf
    • http://www.birdlifebotswana.org.bw/sites/default/files/webform/sightings-sketches/12812059159.pdf
    • https://www.blplegal.com/sites/default/files/webform/lolavojirubopikumu.pdf
    • https://www.jwico.com/sites/default/files/webform/23528315583.pdf
    • https://www.dgs-interparts.be/sites/default/files/xufatonapa.pdf
    • http://cicatsalud.com/html/sites/default/files/webform/39809543560.pdf
    • https://www.jts.org.jo/sites/default/files/webform/76938035167.pdf
    • https://www.blplegal.com/sites/default/files/webform/3097059720.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/LPIa9PGmDLg/uplcv?utm_term=bak+revolver+x2
    • https://lib.asu.edu/system/files/webform/midari.pdf
    • https://ec.europa.eu/eip/agriculture/sites/default/files/webform/27560642257.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ecc7.bin
f18c7ab8db04cc60835ed3a35f2eb72d9b2e5823c61c22bd34d4285f4e3f8715
pdf-font-stream PDF embedded font (sfnt) at offset 0xECC7 4872 bytes