Malicious PDF — malware analysis report

Static analysis result for SHA-256 b84360819e54ff43…

MALICIOUS

PDF

77.5 KB Created: 2021-04-07 05:20:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cc3074a5d74ae529b08746c6b75770b5 SHA-1: 2f5dee1e722f12ac9e0607b35e1ffc86575b3896 SHA-256: b84360819e54ff43a4c95bb77bb79c417c3f52ab427f669a6f86e02e2f36defd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URL that, when visited, likely leads to further malicious content or downloads. The document body, though heavily obfuscated, suggests a lure related to educational materials, aiming to trick users into clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=amoeba+sisters+photosynthesis+and+cellular+respiration+comparison+worksheet+answers
    • https://cdn-cms.f-static.net/uploads/4368964/normal_6015a8eb16921.pdf
    • https://cdn-cms.f-static.net/uploads/4490523/normal_60237cef4a508.pdf
    • http://useporte.xyz/top_best_books_to_read_2020zc9sw.pdf
    • https://rurevudo.weebly.com/uploads/1/3/4/2/134265418/wojonogen_fetapiwuj_vovowus_xefukitiroma.pdf
    • https://nesipemuwazona.weebly.com/uploads/1/3/4/8/134881126/dekoxiwugi.pdf
    • http://usacarins.com/gaxebipuduzelizukupgsvh.pdf
    • https://wirafoxojobukof.weebly.com/uploads/1/3/4/6/134608935/dd4fb3d11.pdf
    • http://barcaporirternet-interbank-pe.com/high_flight_poem_framed2jtjn.pdf
    • https://sakixori.weebly.com/uploads/1/3/3/9/133997256/feguma.pdf
    • https://wobofosowipifir.weebly.com/uploads/1/3/0/7/130776138/xebidumetomok-gumurukikuret-sabodonuxewag.pdf
    • https://cdn-cms.f-static.net/uploads/4386822/normal_5fd3423366771.pdf
    • https://cdn-cms.f-static.net/uploads/4365653/normal_606843d8ef9ee.pdf
    • https://cdn-cms.f-static.net/uploads/4418000/normal_6069f63f532f6.pdf
    • http://baugroup.info/i_am_different_but_i_am_perfect_meaning_in_tamil19iu3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gurowozenupifi/62976020753.pdf
    • https://uploads.strikinglycdn.com/files/b950b798-6033-4c51-a279-674a26aa9583/how_does_a_briggs_and_stratton_carburetor_solenoid_work.pdf
    • https://uploads.strikinglycdn.com/files/cf702920-38ef-41ad-af0b-da0da5869cd9/28514270862.pdf
    • https://s3.amazonaws.com/zerejibixupav/inspirational_performing_arts_quotes.pdf
    • https://uploads.strikinglycdn.com/files/ebc2a404-d83a-4723-9584-a1688a3804c8/acorde_musical_en_ingles.pdf
    • https://s3.amazonaws.com/magapeguwabe/detimo.pdf
    • https://uploads.strikinglycdn.com/files/c15b3335-a08d-4a19-bb49-4d08c7c64e6b/83844571304.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f089.bin
3baed7a043ebec979b354be5de8a92a1bc5a7f61106dbb11ec1d98b44f8a72f9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF089 5700 bytes
font_01_sfnt_off000103d2.bin
ec7b8e3e87730e4e26309387141e547cfecb0af113c102a9c88892fa442d9ad9
pdf-font-stream PDF embedded font (sfnt) at offset 0x103D2 10556 bytes