Malicious PDF — malware analysis report

Static analysis result for SHA-256 b79154655d559e45…

MALICIOUS

PDF

89.5 KB Created: 2021-03-03 05:10:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5d2638bf14bb21faf3b9001de2b3d4a8 SHA-1: 2a3b72ebe4ea69f91526935450ca0b48a7c9ad20 SHA-256: b79154655d559e45ccf4ac489fe5366dd3b10e33e418f2b938e1341063c225ca
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The PDF contains an embedded URL that likely leads to a phishing or malware distribution site. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to redirect users to malicious content, potentially exploiting PDF vulnerabilities or social engineering tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=amscope+best+microscope+camera
    • http://josumewemuzob.getenjoyment.net/50824460618.pdf
    • https://jipofaxinevafud.weebly.com/uploads/1/3/4/3/134350183/c75cee.pdf
    • https://static.s123-cdn-static.com/uploads/4415944/normal_5feb0bdf1e504.pdf
    • https://cdn-cms.f-static.net/uploads/4530846/normal_603b4e29a51ba.pdf
    • https://cdn-cms.f-static.net/uploads/4470841/normal_6011bdf132d54.pdf
    • http://goossyy.online/how_do_you_fix_a_keurig_that_wont_brewjgbak.pdf
    • https://fuzewejobedogu.weebly.com/uploads/1/3/1/4/131482867/dubodubelunid_lotiwumegezage.pdf
    • http://setokanekema.mygamesonline.org/how_to_load_bobbin_on_singer_simple.pdf
    • http://sdfafq.info/computer_related_full_form_listolv25.pdf
    • https://cdn-cms.f-static.net/uploads/4527357/normal_603bc870f0525.pdf
    • https://cdn.sqhk.co/nebafori/ihagdhc/wemefijedaniwalowimeku.pdf
    • https://xorapuwo.weebly.com/uploads/1/3/0/8/130873927/sukifubenoru-zabefarimini-fijivupo.pdf
    • http://fajiriduxir.medianewsonline.com/ar_15_scope_with_laser.pdf
    • https://static.s123-cdn-static.com/uploads/4404503/normal_5fe44db4e51dd.pdf
    • http://feelslike35.com/sony_xplod_speakers_for_cariul7w.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zevesijuduma.atwebpages.com/petit_prince_chapter_3_summary.pdf
    • http://gixiluvigatekij.atwebpages.com/noxepofinaxevuwe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010c14.bin
33d84be8325215330c0fa7e7bb07e07cbd00865fa8572ddd18d0b690db8290f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C14 5176 bytes
font_01_sfnt_off00011d91.bin
fdd6357f047ed0b8ed3bd5def9d9c3a158e3f1616ca147c2cd215ff898a5a2b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D91 10996 bytes
font_02_sfnt_off0001432e.bin
ead7fd593d7f5feef6f283420e9b55f8fa4552f107c64b0063d474dd3355abd8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1432E 16164 bytes