Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba693f1dc73325d5…

MALICIOUS

PDF

76.2 KB Created: 2021-03-07 09:12:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 86bf708a2f85279dcde497177d968040 SHA-1: d76d57be0e1f2fc1d81913dda2097b32c6be9f6f SHA-256: ba693f1dc73325d56e5db2bedb01640be041fc3bbf01f95db9402331d5e8fd1a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an external URI pointing to a suspicious domain, identified as malicious by ClamAV and an ML classifier. The embedded URL suggests a phishing or malware distribution attempt, likely to trick users into downloading further malicious content. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf' and 'Qt', indicating it was generated by a tool rather than being a legitimate document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/aws?utm_term=how+to+reset+acer+mini+laptop
    • http://reflectionss.space/uc_neopets_guidetycuv.pdf
    • https://cdn.sqhk.co/linidivez/QHX4yjc/rinotamufipekofu.pdf
    • https://cdn.sqhk.co/temejikowewa/8ni7Cgf/synchrony_bank_customer_service_payment.pdf
    • http://viewcreditscore.info/used_toro_timecutter_z4200_for_salecyvih.pdf
    • http://xefopuro.mypressonline.com/eye_has_not_seen_nor_ear_heard_kjv.pdf
    • http://urolog.xyz/roman_numbers_worksheet_for_grade_50eopk.pdf
    • http://futup.ru/fumamisohdcxc.pdf
    • http://ekzo-fruit.ru/how_to_draw_a_cat_step_by_step_pictures8a5x4.pdf
    • http://ramuwesitavoz.mywebcommunity.org/tapilobe.pdf
    • https://cdn.sqhk.co/nasanoroge/ggihg9u/sound_assistant_jobs_manchester.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://535a9070-e28a-464b-adc5-c02ad08be00b.filesusr.com/ugd/9df9d6_25f318b8437a476c84ca1e7eae2446e1.pdf?index=true
    • https://c72a6d71-2fad-4f5a-8b7a-a7c165485bce.filesusr.com/ugd/a4966f_e7b1fb60762f483abd5abe28e6332a50.pdf?index=true
    • https://s3.amazonaws.com/liwara/area_of_compound_shapes_worksheet_kuta.pdf
    • http://lifobem.myartsonline.com/nikebuzave.pdf
    • https://s3.amazonaws.com/sogovekevi/calculus_larson_9th_edition.pdf
    • https://s3.amazonaws.com/vogubivajavofu/92386353788.pdf
    • https://ce2645ba-e89a-43d5-afff-5c0150757291.filesusr.com/ugd/c63dba_6fc6328ac52b4d4590aea53d6295488a.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e61648a8-396c-4973-bc54-ed311a76bdfa/zoom_h1_mic_input.pdf
    • https://s3.amazonaws.com/fuzafuzeruwit/android_go_rom_for_samsung.pdf
    • https://uploads.strikinglycdn.com/files/d9299f49-d725-406b-b71d-e5dd4777abb3/duromax_xp4400eh_dual_fuel.pdf
    • https://73f4d879-981c-49fe-abc7-520f36a14a84.filesusr.com/ugd/b77b08_6c5753f0529d4b3e9cdac6ec91241672.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee09.bin
b12ba5a8b460de59d84d73321cae3e6949e45e0c1e0b0230cb0af0fbb26c165c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE09 5132 bytes
font_01_sfnt_off0000ff76.bin
2217e823c1f02bdf95b533fce1f0a6a1380dba667f40e807e151b125a67ad916
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF76 10620 bytes