Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc8cbf85bc19f9ec…

MALICIOUS

PDF

84.2 KB Created: 2021-05-25 05:05:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 71b973844e536b052f72997c2265836f SHA-1: d01608054c2e7ae3754567a70ea132fdfe41b3bd SHA-256: bc8cbf85bc19f9ec90178e8a07653e0732da47776e2919ba74d5e4bed0bcd702
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for an external URI pointing to a suspicious domain, and ClamAV detection confirms it is malicious. The embedded URL suggests a phishing or social engineering lure, likely intended to direct the user to a malicious site for further exploitation. No scripts were extracted, but the overall structure and external URL indicate a phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/strik?utm_term=what+is+craftsmanship+in+art
    • https://cdn-cms.f-static.net/uploads/4499942/normal_606e546242aee.pdf
    • https://cdn-cms.f-static.net/uploads/4412382/normal_6062765667edd.pdf
    • https://jadikabejoza.weebly.com/uploads/1/3/2/7/132740193/1324503.pdf
    • https://ketodoligas.weebly.com/uploads/1/3/4/3/134384615/rupizofek-feviv-vifiwunaz.pdf
    • https://cdn-cms.f-static.net/uploads/4462096/normal_605315e9ae7ed.pdf
    • https://tevoletefe.weebly.com/uploads/1/3/1/6/131606261/9275778.pdf
    • https://kalaxokesipak.weebly.com/uploads/1/3/4/8/134888683/254a932d6.pdf
    • https://cdn-cms.f-static.net/uploads/4419826/normal_6030e0e2a9ade.pdf
    • https://cdn-cms.f-static.net/uploads/4424036/normal_604ae680d508b.pdf
    • https://static.s123-cdn-static.com/uploads/4367944/normal_5fcc4481c48db.pdf
    • https://zubikazosiz.weebly.com/uploads/1/3/4/7/134761183/dijewopowafemijotu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f4b630fe-8702-4872-827c-1bf9204a8d40/34132981180.pdf
    • https://s3.amazonaws.com/tadevewuju/zeloxosidimafezevoxiwakab.pdf
    • https://s3.amazonaws.com/sudevejerifu/jiwoxinov.pdf
    • https://uploads.strikinglycdn.com/files/9b9b9960-5b48-452b-acf9-83b51e524c4e/how_to_use_the_big_easy_oil-less_turkey_fryer.pdf
    • https://uploads.strikinglycdn.com/files/9a374339-8abd-4754-9a1e-366211501c14/speech_class_for_high_school_students.pdf
    • https://s3.amazonaws.com/povelenavuviw/verbal_reasoning_examples_gre.pdf
    • https://uploads.strikinglycdn.com/files/f027a65b-8b20-4a73-8ffd-65a58b8896ea/compound_shapes_area_worksheet_tes.pdf
    • https://uploads.strikinglycdn.com/files/cac446cf-da01-43eb-8cb0-28078b74665c/problemas_ambientales_en_estados_unidos_2020.pdf
    • https://uploads.strikinglycdn.com/files/2d9afef2-ec8f-47f6-9556-62faf6d24b82/57607706558.pdf
    • https://s3.amazonaws.com/xanunafojuloki/difebakexamesuvo.pdf
    • https://uploads.strikinglycdn.com/files/ff0d7bea-42c9-48c1-9cf9-82f877edd0aa/borobolenolaronejiv.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010960.bin
1e7878e22a0f01777bdf45f416d94aad0a54cf624d16752c608f7344014e7910
pdf-font-stream PDF embedded font (sfnt) at offset 0x10960 5236 bytes
font_01_sfnt_off00011b16.bin
7f60cefe7577fd0b69bd9dda498c7a874236e1e521239cfc46e7d8551d960e5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B16 11724 bytes