Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb67e2cf2a432220…

MALICIOUS

PDF

86.1 KB Created: 2021-03-03 17:21:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a0113f2098016fbfb344365bc6437bf5 SHA-1: 6ea31da7bc1da95d9e484b638e5529daa180a712 SHA-256: bb67e2cf2a432220c5c9e3c8a647558826196fcf51ee67ab470baf84dc52c8af
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that, when clicked, leads to a phishing page disguised as information about airline carry-on sizes. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or credential harvesting. No scripts were extracted, but the presence of external URIs and the document's deceptive content point to a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/aws?utm_term=what+size+carry+on+do+most+airlines+allow
    • https://cdn.sqhk.co/bilexodofose/hchiaib/75062625726.pdf
    • https://static.s123-cdn-static.com/uploads/4476783/normal_5ff5f5c6a6736.pdf
    • https://cdn.sqhk.co/jabosuve/cEhhPjh/offer_to_buy_car_through_paypal.pdf
    • https://cdn.sqhk.co/panafilaputu/jjk4hgf/large_fish_tanks_for_sale_melbourne.pdf
    • http://lifolibi.sportsontheweb.net/99989512731.pdf
    • http://zitokujamu.mypressonline.com/sagitak.pdf
    • http://zakewabo.scienceontheweb.net/the_birds_and_the_bees_please_song.pdf
    • http://sagedix.medianewsonline.com/30134529915.pdf
    • http://taforojujutusig.mygamesonline.org/troy_bilt_lawn_mower_belt_replacement.pdf
    • https://cdn.sqhk.co/pesamelez/zifFjbh/bubble_shooter_games_free_download_for_mobile.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/xamapebonijos/maths_sheets_for_grade_1_printable.pdf
    • https://s3.amazonaws.com/lorifumofelu/bsc_civil_engineering_syllabus.pdf
    • https://s3.amazonaws.com/rijaliwiguvex/58033908945.pdf
    • https://s3.amazonaws.com/bivanud/blaupunkt_lcd_tv_manual.pdf
    • https://s3.amazonaws.com/rurovikejigibu/business_letter_report_definition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f127.bin
d930cf85e8bb85122fa0b0364094b3e9fcd0ade77ed9f40c00dcc60a905cb5af
pdf-font-stream PDF embedded font (sfnt) at offset 0xF127 5224 bytes
font_01_sfnt_off000102d6.bin
93e887e258fa95efcda49acea1b54dea725dce4bce6c3160f5526f50d08e6b75
pdf-font-stream PDF embedded font (sfnt) at offset 0x102D6 10744 bytes
font_02_sfnt_off000127a6.bin
159427b32ed66bfbde86def5e6c2992bde67dfb25400c4000a37c9b59b949b61
pdf-font-stream PDF embedded font (sfnt) at offset 0x127A6 16140 bytes
font_03_sfnt_off00013ca2.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x13CA2 4324 bytes