Malicious PDF — malware analysis report

Static analysis result for SHA-256 af3c7f8cf8fb7a8e…

MALICIOUS

PDF

76.9 KB Created: 2021-03-28 06:31:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ad09c2341f8d2a9613b94e4235dabd80 SHA-1: 757ad9dae5473498635fd02a42cd9d0055b5db22 SHA-256: af3c7f8cf8fb7a8e032009dc3199f4cfb63ffe5b3d9a05ed3c8f55d92ed193f0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded URLs that lead to suspicious domains, suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a phishing lure, likely attempting to redirect the user to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9960

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=forever+21+promo+july+2020
    • http://laxana.ru/lofefuwixes9uxh.pdf
    • http://ru-en.xyz/vasusi2dj8t.pdf
    • http://about-central.com/75313527200lulb7.pdf
    • http://copyrightsafetyhelps.com/45147885975apgnx.pdf
    • http://dvertsoff.ru/5498784342ssbcr.pdf
    • http://gallery-shop.site/how_to_decorate_a_white_christmas_tree_in_bluelne8l.pdf
    • http://nikaold.site/pazowulewodazijts9q.pdf
    • http://idealica-columbia.site/71948764415v53t.pdf
    • http://haustova.com/dipiv7tp83.pdf
    • http://naturfresh.space/dafuvajadovigomy60a.pdf
    • http://myluckybet.xyz/ludimizejojdhmhr.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/numunenoji/65777463807.pdf
    • https://uploads.strikinglycdn.com/files/cffb1518-e4b0-4bf9-8469-347d57852584/salidulajusutabowuluxawes.pdf
    • https://438e95ed-c264-4db5-88d3-1a9ca8b91b86.filesusr.com/ugd/733c1f_98a693c45e4e407cbf9be45cd1d8960a.pdf?index=true
    • https://uploads.strikinglycdn.com/files/f292ca6f-c9ea-48a4-965c-90cab0786534/zuriwij.pdf
    • https://uploads.strikinglycdn.com/files/cafd173a-b49a-470b-8add-a491a0df1213/fallout_4_map_size_vs_gta_5.pdf
    • https://0c241ebc-151b-48bf-a4db-a9f2ee65d67b.filesusr.com/ugd/c17081_2585c6b5bb9f43afaac0f865221f6a86.pdf?index=true
    • https://ad323f3e-245e-4e3c-8b16-de91fefec063.filesusr.com/ugd/5ea691_1042e64d8aed4666a4adfff5e3e420c4.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e4522c06-66f5-44cb-a51e-9f4db17934d5/books_of_the_bible_bookmark_template.pdf
    • https://s3.amazonaws.com/padadutiseni/tulanibum.pdf
    • https://s3.amazonaws.com/fazujo/16391002714.pdf
    • https://s3.amazonaws.com/rumezo/classic_wow_dwarf_priest_leveling_guide.pdf
    • https://s3.amazonaws.com/mixanaz/71132926404.pdf
    • https://uploads.strikinglycdn.com/files/393947a7-be7c-437e-a146-00e26cbbb823/87464280659.pdf
    • https://11627308-8c8f-4f08-99ed-0ad85160907d.filesusr.com/ugd/682d1c_1bc61e12f88042628dc5f19a81c2135f.pdf?index=true
    • https://b998fa74-583e-446a-a2a7-67f41460fdb2.filesusr.com/ugd/e081f8_05b9b28ae0da4682b157f8ad65ce9006.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f062.bin
2deeda834ac2c2c178428a1e87ba6ce1f343593bbfcd9f357ecf7d6a7ecde3d3
pdf-font-stream PDF embedded font (sfnt) at offset 0xF062 5096 bytes
font_01_sfnt_off000101c3.bin
d0205b625dd6c2e5153c07c42aef6de67aa3d7802e3c2cd122e9929406b9ad77
pdf-font-stream PDF embedded font (sfnt) at offset 0x101C3 10720 bytes