Malicious PDF — malware analysis report

Static analysis result for SHA-256 b49ee7b88be06988…

MALICIOUS

PDF

83.1 KB Created: 2021-05-21 06:54:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f27228bdae027e7ffad100c879d2c2cf SHA-1: 7c7db9b63f410189e2130528e700e4b8864815e9 SHA-256: b49ee7b88be0698827c282ac8cf712a2a65dca5e453525d2e1f7771eb7a14006
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains embedded URLs that likely lead to further malicious content or phishing sites. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest an attempt to redirect the user to a malicious resource, consistent with phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.lokalesichtbarkeit.de/wp-content/plugins/super-forms/uploads/php/files/ui6rcv6mv8c4vkrjuihlssphmu/7210398242.pdf
    • http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607cd90dc5286---14739906735.pdf
    • https://nicemexico.net/wp-content/plugins/formcraft/file-upload/server/content/files/16098e48b89a47---gojobojofakugugefogi.pdf
    • http://lirealestatelitigator.com/wp-content/plugins/super-forms/uploads/php/files/683abecdfa6bb121d8cc160dec0edc6a/18919452560.pdf
    • http://www.training4thefuture.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a7188bb6469---novat.pdf
    • https://www.ayersworthglen.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608455ff7298b---37064909606.pdf
    • https://myupfield.link/wp-content/plugins/super-forms/uploads/php/files/h7escc7d9se0k73dlpaji1sb1t/bipubekagaxodivodubesanul.pdf
    • http://aimic.com/userfiles/file/fegevejipegobotefozij.pdf
    • https://www.clubmanizales.com.co/wp-content/plugins/formcraft/file-upload/server/content/files/1607eef1a8c3bb---kutuzulegojifamepemubivaw.pdf
    • http://www.jcca.co.in/wp-content/plugins/formcraft/file-upload/server/content/files/160a32a4609631---75351873991.pdf
    • http://3handseg.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080c3d571c0d---bofuzebiloxifopatidosapi.pdf
    • https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/qlfom2l7m1e2oafjvlk7iflnkj/kizikode.pdf
    • https://www.tessilgiada.it/wp-content/plugins/formcraft/file-upload/server/content/files/160a1652ee5005---650316205.pdf
    • http://www.kidnuri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607828bbd091b---numevoxubowaladopolozam.pdf
    • https://reifenscho.de/wp-content/plugins/formcraft/file-upload/server/content/files/160823167ec4f9---96476575977.pdf
    • https://championsforchildren.org/wp-content/plugins/super-forms/uploads/php/files/22626b816745e0a2196403531f74fc69/zixezojawitip.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/skout/mBVl/~3/S30rS-6n6vg/uplcv?utm_term=le+loup+est+revenu+tapuscrit+word
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fddf.bin
467e35f4892233761f70b39b8e657eb96c1a78f7f716b7bfd54d9497f089d0fb
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDDF 5160 bytes
font_01_sfnt_off00010f92.bin
e7e5657d0d1c99317c436422e9e0fd033a864621eff7b43c406367216170313e
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F92 16464 bytes