Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae40b91216c1fedb…

MALICIOUS

PDF

112.2 KB Created: 2021-03-16 13:40:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 84f0a4c3b18e81561b6c94cfcd05869b SHA-1: edd1f3f9ccd8a3ec31e8be3aae31d1056333c3be SHA-256: ae40b91216c1fedbf1ddb6fbe9ae29091c2d0ecd22f5e3e769355d5baf3213a3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, identified as a phishing lure related to the housing market. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of external URIs and embedded URLs suggests the document is designed to redirect users to malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=housing+market+definition+pdf
    • http://plafond.xyz/no_puedo_cambiar_el_formato_de_fecha_en_windows_10od9u1.pdf
    • https://static.s123-cdn-static.com/uploads/4366959/normal_5fc9b2afe6406.pdf
    • https://cdn-cms.f-static.net/uploads/4414682/normal_600c521f9c040.pdf
    • http://gomosivuniku.22web.org/gukuwebadozaratuwofopetos.pdf
    • https://cdn.sqhk.co/gotakavapu/XjgvIlP/68976752992.pdf
    • https://cdn-cms.f-static.net/uploads/4427498/normal_5fe63ba61401f.pdf
    • https://wanusasa.weebly.com/uploads/1/3/1/0/131070791/f79bd5.pdf
    • https://cdn-cms.f-static.net/uploads/4476445/normal_5fd819d405a69.pdf
    • http://cactusvpn.live/toronto_notes_2019_couponiv8kj.pdf
    • https://zejebamusij.weebly.com/uploads/1/3/2/3/132302936/wovemipopikidojivu.pdf
    • http://monidokazuxawop.22web.org/7813635942.pdf
    • http://itclick.pro/433461811829ku9w.pdf
    • https://cdn.sqhk.co/savunowudob/gteKKzL/vitamin_b12_overdose_nhs.pdf
    • https://cdn.sqhk.co/wirowanorax/ge3FSia/gifad.pdf
    • https://cdn.sqhk.co/talexadu/eijigMF/42105430947.pdf
    • https://static.s123-cdn-static.com/uploads/4459320/normal_5fe44e7c1b8b4.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://xelurutokige.rf.gd/sibedewugutosad.pdf
    • https://uploads.strikinglycdn.com/files/b94ce5df-999b-47fb-8a93-7a63b0fca559/what_is_the_mail_recovery_center.pdf
    • http://zoregok.rf.gd/excel_set_worksheet_name_vba.pdf
    • https://uploads.strikinglycdn.com/files/ad649a18-4d2e-4fe0-a984-5eb4bd6ac615/41330768853.pdf
    • http://larujuzo.rf.gd/tasipi.pdf
    • https://uploads.strikinglycdn.com/files/7fc1a612-d271-4382-b824-e77837a55deb/how_to_draw_classes_online_for_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017747.bin
a30aebcc8b13c93fe0d9544352e03e67b4124ca4253aaae6fe9b88270db2df33
pdf-font-stream PDF embedded font (sfnt) at offset 0x17747 5352 bytes
font_01_sfnt_off00018965.bin
d499b00cc78d8ed6cf81f63876d0c079573b87ae6fe4b377257af549b0dcf13c
pdf-font-stream PDF embedded font (sfnt) at offset 0x18965 12820 bytes