Malicious PDF — malware analysis report

Static analysis result for SHA-256 a82ad52579cb4403…

MALICIOUS

PDF

85.3 KB Created: 2021-04-05 11:53:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 285dee5fdea7a0f6dbc0cc0cbea48151 SHA-1: 1a4ba66ab0fc580a6440dbcaca338d221a476289 SHA-256: a82ad52579cb44038abcbb97f8e69b1e07d9cd75d7cd9a44dec3e368ed92ce6c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into clicking it. The document body, though heavily obfuscated, appears to be a malformed attempt to disguise the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=what+is+the+main+message+of+malala+speech
    • https://fulopovesaj.weebly.com/uploads/1/3/0/7/130740112/4258910.pdf
    • https://kuxokovu.weebly.com/uploads/1/3/0/7/130738635/dbc9ce.pdf
    • https://nogovomavidel.weebly.com/uploads/1/3/1/6/131637041/5f95423a2508.pdf
    • https://cdn.sqhk.co/vapitinab/igeaje2/989813372.pdf
    • https://cdn.sqhk.co/rawerusiwala/ChiLWrG/palulogulu.pdf
    • https://nobenore.weebly.com/uploads/1/3/2/6/132696051/bafidabejebidof_xerekizitovare.pdf
    • https://puzugisebo.weebly.com/uploads/1/3/1/4/131438758/sajexumasex.pdf
    • https://cdn.sqhk.co/lanasido/4uhbtnx/7613932566.pdf
    • https://cdn.sqhk.co/luvafuza/hfjfzha/rababumo.pdf
    • https://cdn.sqhk.co/moxinivo/8gj4jg8/shanghai_disney_resort_email_address.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://kexeban.rf.gd/wubisajatovizores.pdf
    • https://s3.amazonaws.com/xasovewipeje/57518508201.pdf
    • https://s3.amazonaws.com/pobixedele/campaign_finance_reform_ap_gov.pdf
    • https://uploads.strikinglycdn.com/files/65ee78a5-92be-4ae2-b96c-2b46c090b0ad/how_many_picture_cards_in_52_deck.pdf
    • https://uploads.strikinglycdn.com/files/fccabe7e-8ffe-4dd8-b9ed-f2589a011e8f/gajigixenoraga.pdf
    • https://s3.amazonaws.com/sojebelevenex/sample_staff_meeting_agenda_format.pdf
    • https://uploads.strikinglycdn.com/files/270e8060-6f5e-4bef-9d5b-89711bed9178/98158374838.pdf
    • http://xitemefunugege.epizy.com/add_checkbox_to_excel_spreadsheet.pdf
    • http://rigutogivopum.epizy.com/82712484156.pdf
    • https://uploads.strikinglycdn.com/files/b31e0055-3d41-43b4-8046-bac60e59ceed/sijax.pdf
    • https://uploads.strikinglycdn.com/files/7b93f286-6a4d-4578-8fa0-ef762737e4f7/hp_laserjet_p3015_driver_for_windows_7_64_bit_free_download.pdf
    • https://s3.amazonaws.com/pevuwarobuvowa/brain_death_criteria.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f71c.bin
5cd3c36cf3fbcda34c079430c6448f82c8d60f593fbafba3cc56797fed197508
pdf-font-stream PDF embedded font (sfnt) at offset 0xF71C 5132 bytes
font_01_sfnt_off0001087b.bin
a8ba320a0ac8a73a5a8cc2c47ba30bd151ec5f51af4d5ac0b9daf85eaa8f1301
pdf-font-stream PDF embedded font (sfnt) at offset 0x1087B 1936 bytes
font_02_sfnt_off000111c0.bin
36dc359a605a9cc131edffb296de085a2f9bf5ace0f59a5eb9740f9a18fe01f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x111C0 11424 bytes
font_03_sfnt_off0001389f.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x1389F 4324 bytes