Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1d634f6f29ebeb1…

MALICIOUS

PDF

91.8 KB Created: 2021-03-10 01:45:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3b2dd486d038d49b92ba592870ccce8a SHA-1: b12676effaf46adacd9f69af4969afbebc3639fe SHA-256: b1d634f6f29ebeb12fd5f71cfa56b940b9492b3e558ce26db4d7d3bd2e288b36
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document identified as malicious by ML classifiers and ClamAV. It contains an embedded URI pointing to a suspicious domain, likely intended to host a malicious payload or phishing content. The document body, though heavily obfuscated, suggests a lure related to 'Virgilio bucoliche'. No scripts were extracted, but the presence of an external URI is a strong indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=virgilio+bucoliche+pdf
    • https://cdn-cms.f-static.net/uploads/4417808/normal_6040e9b71aa4f.pdf
    • http://peteferix.mypressonline.com/89326681569.pdf
    • https://cdn-cms.f-static.net/uploads/4489259/normal_5fd7f8e218e3f.pdf
    • http://nosilekexiwot.mywebcommunity.org/rozem.pdf
    • http://vijuziruzunubiz.iblogger.org/pevikixujasivoxo.pdf
    • http://zobebukore.22web.org/likuziwixalakupubademor.pdf
    • http://xarubuxa.iblogger.org/walezanomirezava.pdf
    • https://static.s123-cdn-static.com/uploads/4450046/normal_5ffd464985c76.pdf
    • http://wemuwetafivaxe.sportsontheweb.net/65556906770.pdf
    • http://posebakuxosafod.getenjoyment.net/90899954838.pdf
    • http://duzegipim.22web.org/kisalibelikokesuwi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gaxunexuxulaxed.epizy.com/risugek.pdf
    • http://kinosunun.epizy.com/85682475918.pdf
    • https://s3.amazonaws.com/patilawasu/cards_against_humanity_expansion.pdf
    • https://uploads.strikinglycdn.com/files/7f6c507e-26d4-4bab-b8e3-31c3a657fe87/6126540978.pdf
    • https://s3.amazonaws.com/xomudufe/35745005936.pdf
    • http://difedomuki.epizy.com/48836064129.pdf
    • http://ravesezubepad.epizy.com/jumod.pdf
    • https://uploads.strikinglycdn.com/files/b9afc2a4-97e5-42c2-a69d-611aabfd5bf0/62211469327.pdf
    • https://s3.amazonaws.com/luxaduzimase/best_shooting_games_for_android_under_100mb.pdf
    • http://popofisofol.myartsonline.com/nosezofepexokamakurir.pdf
    • https://uploads.strikinglycdn.com/files/39cda619-32d2-48e0-a685-d138fef3fbf2/salary_of_a_medical_lab_technician_in_kenya.pdf
    • http://nafakosoleg.epizy.com/14996831563.pdf
    • https://s3.amazonaws.com/tiluwisulepam/street_map_bruges.pdf
    • http://vuwofaxanubus.epizy.com/the_standard_dental_insurance_login.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000123dc.bin
7619ba56c576f01625411ee20fdd0761cf30cb8d88b3921b063c3dc1023cbfe9
pdf-font-stream PDF embedded font (sfnt) at offset 0x123DC 5132 bytes
font_01_sfnt_off00013553.bin
53106a6c93e9c67ed7d90034cd6a6f859144102376483c1b6534bdb73bd9091f
pdf-font-stream PDF embedded font (sfnt) at offset 0x13553 14400 bytes