Malicious PDF — malware analysis report

Static analysis result for SHA-256 b283e3737fc64813…

MALICIOUS

PDF

68.5 KB Created: 2021-03-16 04:41:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 057c3ae15af8dba7ae6a59d27f36a374 SHA-1: 1e5a9d6e1ae22713bebeb0ac30417fa77532f110 SHA-256: b283e3737fc648139630b72f7fb45560feb50e2c1d0f7a709c04dc2d5e277c6e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that leads to a domain associated with phishing. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to trick users into downloading further malware or providing sensitive information. The document body, though heavily obfuscated, suggests a lure related to educational content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=super+ultimate+graphing+challenge+worksheet+answer+key
    • https://cdn-cms.f-static.net/uploads/4421937/normal_60390c654360b.pdf
    • https://cdn-cms.f-static.net/uploads/4446642/normal_6022e24d2b33a.pdf
    • https://cdn.sqhk.co/gibuzini/hfhigje/nakizodutavaxotosoteji.pdf
    • http://xatitakuv.iblogger.org/mivawetizowukoz.pdf
    • https://cdn.sqhk.co/nulusezitelo/Yuqojcl/89157934221.pdf
    • http://myfirstsite.xyz/how_to_draw_equation_graph_in_excelpbj8w.pdf
    • https://bezofaxifi.weebly.com/uploads/1/3/1/6/131606652/51a0a441ce8e248.pdf
    • https://xukanodipu.weebly.com/uploads/1/3/4/8/134885825/7b93002.pdf
    • https://cdn-cms.f-static.net/uploads/4449419/normal_6018f898a14c4.pdf
    • https://cdn.sqhk.co/xeposetuge/ghe5vxM/weed_factory_idle_mod_apk_1._12._30.pdf
    • https://static.s123-cdn-static.com/uploads/4391899/normal_5fe269cee8b37.pdf
    • https://cdn.sqhk.co/tavolimogid/iq6ibKH/tumblebook_library_app.pdf
    • http://joblanc.xyz/les_miserables_how_many_pagesz97i5.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://nizalag.rf.gd/necchi_544_sewing_machine_price.pdf
    • http://taxifegizuni.epizy.com/aadhalal_kadhal_seiveer_movie_tamilyogi.pdf
    • http://vokulokunupada.epizy.com/9718870497.pdf
    • http://jatomije.rf.gd/dell_optiplex_9010_lan_driver_free_download.pdf
    • http://wegarasuw.epizy.com/grocery_list_template_numbers.pdf
    • http://zaxukesaludu.epizy.com/votenusuvaxesoxobez.pdf
    • http://vilewol.epizy.com/momofuku_pork_belly_recipe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ccfe.bin
8a7d2f81408bbfbf6002338281f6a4f5a556827c1139fda1ca68d942a6337d23
pdf-font-stream PDF embedded font (sfnt) at offset 0xCCFE 5708 bytes
font_01_sfnt_off0000e054.bin
d7ac0db4b7f0534aa18d954f4f59cb3bf12764bc3cd63ee3488b597c958e7ecd
pdf-font-stream PDF embedded font (sfnt) at offset 0xE054 10008 bytes