Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2200df15bbf6d32…

MALICIOUS

PDF

87.9 KB Created: 2021-03-19 12:09:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: bc8be6263ec561cce550fee0c75ca0c1 SHA-1: e3fee6711bf0df53b8047fc29ba722812970bcb8 SHA-256: b2200df15bbf6d32e4aecef5150302afff7c2ed59258a38c3d74715479cac1da
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an embedded URI pointing to a suspicious domain, identified as malicious by ClamAV and ML classifiers. The document body, though heavily obfuscated, suggests a lure related to 'introduction centrifugation pdf'. The presence of multiple unknown URLs further supports a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=introduction+centrifugation+pdf PDF link annotation
    • http://sallehq.xyz/2214657317q5fmj.pdfIn PDF document text
    • http://arthromedshop.xyz/what_is_a_deviance_in_sociology1sa18.pdfIn PDF document text
    • https://cdn.sqhk.co/muxigatatini/hgrha8q/mugotexefajijag.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4446283/normal_5fd84547777fa.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454436/normal_60380649ccebe.pdfIn PDF document text
    • https://cdn.sqhk.co/jiluputumusi/mVje3ih/battleship_potemkin_baby_carriage.pdfIn PDF document text
    • http://prazdnikprosto.ru/aplikasi_codashop_mod3j526.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4494436/normal_604f6b0bb8144.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4387242/normal_5fe42e5e42317.pdfIn PDF document text
    • https://cdn.sqhk.co/ruperodu/jdii0kq/bedrock_2._0_addon_mcpe.pdfIn PDF document text
    • http://xrootunited.com/whatsapp_latest_version_upgrade0mcpt.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4416927/normal_5fcb69c5b3845.pdfIn PDF document text
    • http://wenenejenataf.iblogger.org/48340804883.pdfIn PDF document text
    • https://cdn.sqhk.co/gixelotopa/cSicgjW/most_free_kick_goals_record.pdfIn PDF document text
    • http://normab-id.com/nefaboxeduxotijidime1oab.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/kujesulad/eine_kleine_nachtmusik_easy_piano_sheet_music.pdfIn PDF document text
    • https://s3.amazonaws.com/kewakuko/jatibeva.pdfIn PDF document text
    • https://s3.amazonaws.com/lixuzo/gift_certificate_template_free_psd.pdfIn PDF document text
    • http://turimovikukori.epizy.com/get_your_guide_customer_service_uk.pdfIn PDF document text
    • https://s3.amazonaws.com/vajefam/bharathi_kannamma_songs_starmusiq.pdfIn PDF document text
    • https://s3.amazonaws.com/geradi/asphalt_8_cheats_android_online.pdfIn PDF document text
    • http://tadezaxe.rf.gd/88995307644.pdfIn PDF document text
    • https://s3.amazonaws.com/baritexovopa/the_wolf_among_us_apk_full_game.pdfIn PDF document text
    • https://s3.amazonaws.com/divelatoxa/74847500618.pdfIn PDF document text
    • https://s3.amazonaws.com/kavugusepe/lorilidadonepujojuzi.pdfIn PDF document text
    • http://nenutufap.epizy.com/80286964275.pdfIn PDF document text
    • http://jatuxijor.epizy.com/the_bell_jar.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000117a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x117A8 5048 bytes
SHA-256: ccd12a35775aa229ddac2f02a542859b67fae096e53824f14558bbe580ba89e2
font_01_sfnt_off000128ea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x128EA 12064 bytes
SHA-256: 68516977f34abb946776f25f874690d08e1f3a2b0dc7d8efbe98cb2616324f16