Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8a8311ed102ccdd…

MALICIOUS

PDF

66.9 KB Created: 2021-06-01 20:32:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fabfc2f81e5d8531879699c4061ad3e1 SHA-1: 62820740f4f6a64a36657bf6d0b1e9b1faf9f242 SHA-256: a8a8311ed102ccddfc4ab4d4b7c184031ecbf788a09a2436e017aa0333fc9680
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL, 'https://wastran.ru/pbw?utm_term=qual+feriado+de+hoje', is the primary indicator of a potential phishing or malware distribution site. Although no scripts were explicitly extracted, the PDF structure and the presence of an external URI suggest it is designed to redirect the user to a malicious resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://wastran.ru/pbw?utm_term=qual+feriado+de+hoje
    • https://cdn-cms.f-static.net/uploads/4370744/normal_606cc884a6861.pdf
    • https://cdn-cms.f-static.net/uploads/4445573/normal_60123ab46af83.pdf
    • https://static.s123-cdn-static-d.com/uploads/4389365/normal_60b1b0add5e1e.pdf
    • https://cdn-cms.f-static.net/uploads/4454811/normal_6063a5bd9d677.pdf
    • https://cdn-cms.f-static.net/uploads/4463794/normal_601ad455f1453.pdf
    • https://cdn-cms.f-static.net/uploads/4489412/normal_604f085eb1935.pdf
    • https://cdn-cms.f-static.net/uploads/4383679/normal_600f14777c2a8.pdf
    • https://static.s123-cdn-static-d.com/uploads/4386830/normal_60b6232f0fd4e.pdf
    • https://static.s123-cdn-static.com/uploads/4405190/normal_6006d43c2584f.pdf
    • https://cdn-cms.f-static.net/uploads/4385435/normal_60433285c1f4f.pdf
    • https://cdn-cms.f-static.net/uploads/4413112/normal_60425f995bf57.pdf
    • https://static.s123-cdn-static.com/uploads/4386851/normal_5fe1edd50b059.pdf
    • https://static.s123-cdn-static.com/uploads/4448121/normal_5fe0a71d1d014.pdf
    • https://static.s123-cdn-static.com/uploads/4502833/normal_5fc802561db94.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ddf318d4-d630-4e49-8624-17c2a1748a9e/free_timeline_infographic_template_powerpoint.pdf
    • https://uploads.strikinglycdn.com/files/a8da8c1f-67d6-4a06-9da6-915b5a77ded8/zuwodarasekiped.pdf
    • https://uploads.strikinglycdn.com/files/641df652-8f47-439c-a273-65b7f37d5876/us_postal_services_international_shipping.pdf
    • https://uploads.strikinglycdn.com/files/e8146216-edbb-4f66-a5cd-e0ccb35b210c/greek_mythology_story_of_demeter_and_persephone.pdf
    • https://uploads.strikinglycdn.com/files/7c9b4a73-9eb5-4e9b-8577-876858cdf39f/liquid_diet_plan_for_weight_loss_surgery.pdf
    • https://uploads.strikinglycdn.com/files/d7b6ec39-400b-4955-b8dc-4361e4becbef/wojovogepo.pdf
    • https://uploads.strikinglycdn.com/files/ed552198-62f5-4697-b807-fc7cab7fff61/toefl_400_words.pdf
    • https://uploads.strikinglycdn.com/files/84b43f1e-f96d-48bc-940a-2e14eb19d88c/35368084352.pdf
    • https://uploads.strikinglycdn.com/files/e72ae83b-05cc-4013-be76-53e88ccea3eb/panchatantra_story_in_hindi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c98a.bin
0d33be5ef1ce7df2fb195a89804f708e732e62aaed984b11a1d42ec331bb0bb8
pdf-font-stream PDF embedded font (sfnt) at offset 0xC98A 4952 bytes
font_01_sfnt_off0000da60.bin
0d6668ad7a6923d604e0ea398b9ca7883fc7d3874eb659781a65698f80d2a7fd
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA60 10656 bytes