Malicious PDF — malware analysis report

Static analysis result for SHA-256 bba1c423e321ad32…

MALICIOUS

PDF

76.7 KB Created: 2021-03-21 22:14:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f416526100d5caad6ad3f8117d01c410 SHA-1: a3d1ab6d3194ea37ec752e1a80424ca7cdcb8509 SHA-256: bba1c423e321ad3283b7a43f8b4fb81d29d54c5bc3fffca5d68c7e0b4127702b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URL pointing to a suspicious domain, which is likely used to host malicious content or phishing pages. The PDF structure and embedded artifacts suggest it is designed to exploit vulnerabilities or trick users into visiting the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=unite+me+pdf
    • http://nibelv.xyz/what_do_you_do_when_you_feel_like_life_has_no_meaning4g00x.pdf
    • http://lajibodomemebev.66ghz.com/barium_swallow_template_rsna.pdf
    • http://xobukikop.iblogger.org/54459156375.pdf
    • http://podifodosej.scienceontheweb.net/all_about_space_issue_70.pdf
    • http://my-credit.info/87041373201aer64.pdf
    • http://fajujefa.getenjoyment.net/area_problem_solving_worksheets.pdf
    • http://kprovk.xyz/kenmore_90_series_electric_dryer_not_heatingd0fnz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/70979df1-3c7f-44d2-a433-30d536dc38f3/multi_storey_building_meaning_in_hindi.pdf
    • http://limoxukuk.atwebpages.com/how_to_stop_first_alert_alarm_from_chirping.pdf
    • http://kagokonutuvep.epizy.com/79167832141.pdf
    • http://vopobojadufej.rf.gd/does_malaysia_have_nuclear_power_plants.pdf
    • http://lugotimasowe.epizy.com/bee_bot_lessons.pdf
    • https://uploads.strikinglycdn.com/files/7324effd-4aa4-46e2-99bd-05ea0cde2b7f/35041684015.pdf
    • http://danetuxu.rf.gd/salary_of_business_analyst_in_pakistan.pdf
    • http://sinusisokopex.atwebpages.com/sternal_precautions_handout.pdf
    • https://uploads.strikinglycdn.com/files/7ce4c345-bbc2-4e53-8e73-f7787418660a/moto_g6_play_specs_canada.pdf
    • https://uploads.strikinglycdn.com/files/f882e045-e1c6-4a6c-a188-75991e14dfcb/behringer_pmp2000d_powered_pa_mixer_14_channel_2000w.pdf
    • http://minapisifiret.rf.gd/zakida.pdf
    • https://uploads.strikinglycdn.com/files/aaa0abf3-33ff-40be-b593-7bf49c7fb7a4/25544047495.pdf
    • https://uploads.strikinglycdn.com/files/317a5cba-b70c-4208-b05d-87f0115da601/kanemekemodalinem.pdf
    • https://uploads.strikinglycdn.com/files/eaed2a48-fa7f-4eac-b90a-0e3c39abc970/ramoxin.pdf
    • http://bebajowofiz.rf.gd/impact_of_globalization_on_developing_countries.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee9f.bin
8c626d5f1549547341c21170f66f72a874c36841c5109713ac57b6e26cc119ff
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE9F 4664 bytes
font_01_sfnt_off0000fe78.bin
f89fcd35b6c906598dc1e20fabcd946f41b65f6e375535fdcb9a2b1911caa2cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE78 11284 bytes