Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae9f09d0a46a46d9…

MALICIOUS

PDF

223.7 KB Created: 2020-11-19 20:14:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e2b842fa213f2fee57afa2d54e769ee6 SHA-1: d1ddaa0eac0fbb83ec71c8b338efe74cd9f8e73e SHA-256: ae9f09d0a46a46d99b0093fd2b66d057fce75fe80aaeacaad0bf82a687b2b574
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of external URIs and embedded URLs suggests the document is designed to redirect the user to potentially harmful websites. Although no scripts were explicitly extracted, the PDF format can embed JavaScript, which could be used to facilitate malicious actions.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9929

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/123?utm_term=alan+watts+biography+pdf
    • https://tidivexosito.weebly.com/uploads/1/3/4/3/134316292/viremubosajoruz.pdf
    • https://setisobizosepi.weebly.com/uploads/1/3/4/6/134670504/e72a0a2d305982.pdf
    • https://cdn-cms.f-static.net/uploads/4406812/normal_5f93f1f8d8142.pdf
    • https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/862f27556c.pdf
    • https://cdn-cms.f-static.net/uploads/4375086/normal_5fb2776e30fe5.pdf
    • https://kuvikupomudu.weebly.com/uploads/1/3/4/4/134457818/batomob.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.thdl.org/http://www.thdl.org/Tibetan
    • https://s3.amazonaws.com/zopamagiguti/weatherby_pa-08_12_ga.pdf
    • https://s3.amazonaws.com/wegemebufojafak/rcog_guidelines_for_anemia_in_pregnancy.pdf
    • https://s3.amazonaws.com/jenagubadopi/lausd_school_calendar_2016-17.pdf
    • https://s3.amazonaws.com/fasanag/94678512879.pdf
    • https://s3.amazonaws.com/fifuto/captain_buggy_one_piece.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.htmlTibetan

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002f933.bin
e2fccf77f334caae90645d91781319f7445ce75df87402274db2af42adf6a2cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F933 9756 bytes
font_01_sfnt_off0003195f.bin
d1ec38726d7c69cde938cab5bf5592c42b0c33969d63dbf7bbb83be1f0e697bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x3195F 5628 bytes
font_02_sfnt_off00032c9d.bin
1250d2bad25f4ff0fc597f503538010d2bc88f134c755783d7c755877a671b0c
pdf-font-stream PDF embedded font (sfnt) at offset 0x32C9D 10980 bytes
font_03_sfnt_off00034459.bin
e1de11e13f04d5037f531f633de29b26f5402a704d4e73dc16fe373b34910f23
pdf-font-stream PDF embedded font (sfnt) at offset 0x34459 14012 bytes