Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9725e5cef07262a…

MALICIOUS

PDF

69.1 KB Created: 2021-03-25 09:35:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0351f937a6fd35932f72d055b9652304 SHA-1: 7386570009fe4ccc03fd0015a9d908ef71d5d1e2 SHA-256: b9725e5cef07262a445dd552137139f42f394d506d30d9093bfab07d286cb72f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URL pointing to a suspicious domain. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution. The PDF structure and embedded URI heuristic suggest the primary goal is to redirect the user to the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=benim+hocam+t%25C3%25BCrk%25C3%25A7e+video+soru+bankas%25C4%25B1+pdf
    • https://cdn-cms.f-static.net/uploads/4402724/normal_6057bb353585b.pdf
    • https://static.s123-cdn-static.com/uploads/4482230/normal_6003be542544e.pdf
    • http://funseeds.site/how_many_apple_airport_express_on_one_networkfyc5a.pdf
    • https://static.s123-cdn-static.com/uploads/4481552/normal_5ff2379151ad8.pdf
    • https://cdn-cms.f-static.net/uploads/4464877/normal_60136364d157e.pdf
    • http://soldonlakewood.com/dusoborogafujijopineji7tkol.pdf
    • http://instapriz365.site/best_4k_55_inch_tv_under_5005p1wh.pdf
    • http://golosa-spasibo.ru/fenasojejudabasejunolspoe9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dakebesuvum/alcatel_one_touch_retro_flip_phone_sprint.pdf
    • https://s3.amazonaws.com/tapelu/cashflow_game_android_apk.pdf
    • https://s3.amazonaws.com/bubodeliza/linkedin_profile_picture_2018.pdf
    • https://s3.amazonaws.com/lixuduwonifa/mejor_libro_de_gramatica_espaola.pdf
    • https://s3.amazonaws.com/mubemutolewe/the_art_of_manipulation_omar_johnson_free.pdf
    • https://s3.amazonaws.com/laradusa/above_all_power_audio.pdf
    • https://s3.amazonaws.com/zeworibuzoza/pafakapuritusola.pdf
    • https://s3.amazonaws.com/bivanud/small_baby_boy_pics.pdf
    • https://s3.amazonaws.com/nutanigonu/jozalavival.pdf
    • https://s3.amazonaws.com/gulapore/california_king_platform_bed_wood.pdf
    • https://s3.amazonaws.com/wikurixobelu/bow_tie_cinemas_trumbull_connecticut.pdf
    • https://s3.amazonaws.com/daraniwekamidir/who_is_the_antagonist_in_joe_turners_come_and_gone.pdf
    • https://s3.amazonaws.com/jidosatikim/midas_m32r_live_user_manual.pdf
    • https://s3.amazonaws.com/voxulija/jaritaniforanu.pdf
    • https://s3.amazonaws.com/xufoxorog/alone_heart_sheet_music.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cda0.bin
76805e14956c2cebfdbd73c973cea987e82f4fe300f6b2f2e477fbdf215ec94a
pdf-font-stream PDF embedded font (sfnt) at offset 0xCDA0 6008 bytes
font_01_sfnt_off0000e177.bin
a9717392c3d472ca198e74cfbb91b435fa08449f2c447e1f4e6a2b16e84d637e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE177 11060 bytes