Malicious PDF — malware analysis report

Static analysis result for SHA-256 a89dd8cec28c1329…

MALICIOUS

PDF

102.7 KB Created: 2021-03-21 21:36:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a3ea668aecf94796af84183629b87add SHA-1: 40475609c5d0b41c8fdcf7d87617dee50fd8e149 SHA-256: a89dd8cec28c1329bbffbfb387d1b1d44bb35faf64c4cab47b9bb5c2901a6d55
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains numerous embedded URLs, many of which are associated with phishing or malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of embedded URLs suggests an attempt to redirect the user to malicious websites, likely for credential harvesting or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/award?keyword=arte+classica+grecia+pdf
    • http://instofficial.online/state_of_michigan_child_support_tablej68id.pdf
    • http://stixlife.info/whiteboard_animation_software_for_pc_freelmb3j.pdf
    • https://nubipudovolena.weebly.com/uploads/1/3/4/0/134012318/nuratadorozeleduw.pdf
    • https://cdn.sqhk.co/lasumalena/Zjcjhie/android_custom_listview_adapter_in_fragment.pdf
    • https://fogunovavak.weebly.com/uploads/1/3/2/6/132681822/rilurilusejaji-xezebowik.pdf
    • https://cdn.sqhk.co/ganuniwiku/iho71vt/nizesupel.pdf
    • http://setlyb.online/resistor_color_code_chart_calculator2j9w0.pdf
    • http://termo-nord.tech/noguflb7gy.pdf
    • http://aov.one/lose_stomach_fat_in_two_weeksemlo2.pdf
    • https://vemosesagegedow.weebly.com/uploads/1/3/4/3/134312783/f47bfb72.pdf
    • https://cdn.sqhk.co/kigaratak/FijBRiy/nick_jr_claymation_commercial_dora_and_friends.pdf
    • http://ehaberdevlet.com/d_link_dir_601_b_150_homemi2pv.pdf
    • http://reduslim-shop.website/adorno_philosophy_of_new_musica2156.pdf
    • http://podarokinsta.online/how_to_read_control_panel_wiring_diagram2orff.pdf
    • https://komimuvupelogi.weebly.com/uploads/1/3/4/3/134312664/migaxogulinidox-lowevanejajikip-nutetitatovelax-pekeduvizid.pdf
    • http://tekplafond.xyz/how_to_teach_time_management_skillso8abj.pdf
    • https://vasinurevesodux.weebly.com/uploads/1/3/4/6/134605286/4649016.pdf
    • https://xigobiniliw.weebly.com/uploads/1/3/5/2/135298108/latolamez.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/runuzitexokol/67816916341.pdf
    • https://s3.amazonaws.com/zubata/notupodaguvij.pdf
    • https://s3.amazonaws.com/seriposuj/audio_drivers_windows_10_update.pdf
    • https://s3.amazonaws.com/dazovosugev/car_log_book_excel_template.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000150c5.bin
d6209f269ffdcf8d8cf7f57caba6d1130347a626f51028c4070d4f73e894e4d8
pdf-font-stream PDF embedded font (sfnt) at offset 0x150C5 5312 bytes
font_01_sfnt_off000162ea.bin
b9e3340b5013efc89169dda2d6230f8a5e25e707459f6ad773eff64866fbd78b
pdf-font-stream PDF embedded font (sfnt) at offset 0x162EA 14608 bytes