Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6afe4e8826fa777…

MALICIOUS

PDF

73.3 KB Created: 2021-03-17 10:24:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5591c22cb20bc79d295524037bd52170 SHA-1: e70fe12a720e621933166cc81abf8d9cf72ab9aa SHA-256: b6afe4e8826fa777dbf4236e448c0e7496a5d8fd18d43c7ee995effaa8d3e51f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that directs users to a site offering file conversion services, which is a common lure for phishing or malware delivery. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URI suggest it's designed to redirect users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=convert+pdf+to+dwg+online+zamzar
    • http://dudipoviju.22web.org/jokisawaxadijelavik.pdf
    • http://natfreshik.fun/maths_formulas_in_hindi73gce.pdf
    • https://cdn-cms.f-static.net/uploads/4460247/normal_603cf9375a527.pdf
    • http://lafutib.sportsontheweb.net/72864006701.pdf
    • http://lizowaw.scienceontheweb.net/fisher_price_toy_garage.pdf
    • https://static.s123-cdn-static.com/uploads/4450251/normal_600590662df92.pdf
    • http://puveputado.sportsontheweb.net/testament_abraham.pdf
    • http://money-team.site/33960366215vyhdm.pdf
    • http://revodegasiger.sportsontheweb.net/adjetivos_en_ingles_y_espaol_para_describir_personas.pdf
    • https://cdn-cms.f-static.net/uploads/4485152/normal_5fdafd897d95d.pdf
    • http://fomigiv.mypressonline.com/gilajegatenomavera.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://jokubamobivavum.onlinewebshop.net/21375174494.pdf
    • http://bitines.myartsonline.com/amana_80_sse_air_command_gas_furnace_reset_button.pdf
    • https://s3.amazonaws.com/fadedosi/74845723806.pdf
    • https://s3.amazonaws.com/wanalovum/corbett_maths_bidmas_worksheet.pdf
    • http://kepofif.onlinewebshop.net/char_broil_electric_bbq_red.pdf
    • http://wififeju.atwebpages.com/89262398091.pdf
    • https://s3.amazonaws.com/divexikav/lujilunaxiwidoxokawanu.pdf
    • http://xevikosurozogin.rf.gd/formation_biodynamie_colmar.pdf
    • https://s3.amazonaws.com/jotizifime/how_to_factory_reset_h.264_digital_video_recorder.pdf
    • http://sosozodazu.epizy.com/63719540896.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cc89.bin
65cdabe77414ea74fa276b47738d45ad9729b57da55ef567447a91a195255182
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC89 5292 bytes
font_01_sfnt_off0000de96.bin
5a51296158927db1c6ec9efb6c71ab4bc195e3c558a93487279541f05dafceaf
pdf-font-stream PDF embedded font (sfnt) at offset 0xDE96 10460 bytes
font_02_sfnt_off00010263.bin
1ffca1ef16be5e2ec436e77f9211a88ad3199dc781cb76600401cc2e2c7dce6d
pdf-font-stream PDF embedded font (sfnt) at offset 0x10263 16140 bytes