Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd4334b03aaa8d10…

MALICIOUS

PDF

88.8 KB Created: 2021-03-20 22:22:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fbcf84a6d21cbea64bdb29514214483c SHA-1: a0ef44d52cbc691b665ce7708568e08bb66080cd SHA-256: bd4334b03aaa8d10932531b11a5d641e69edc2e74ae0182ba6bd3a9f947c3162
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains heuristics indicating the presence of external URIs and embedded URLs, with one URL specifically matching the document's purported content. The ML classifier and ClamAV detection strongly suggest malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URI point towards a social engineering attack to redirect users to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=cub+cadet+rzt+42+manual
    • http://salonlabs.xyz/tabletop_rpg_games_2021t7ypa.pdf
    • http://lnstagram-verificationbadgeform.com/kovepefwy9n.pdf
    • http://ecosbor.net/facebook_video_to_computer4y3ld.pdf
    • http://mavpa.fun/the_bell_jar_movie_streaming8qsmw.pdf
    • http://my-favshopg.online/the_adventures_of_sherlock_holmes_season_2_episode_6xyixg.pdf
    • http://deutschebank-meine.com/10797336604ns17e.pdf
    • http://samoe-samaya.ru/scott_pilgrim_vs_the_world_game_pre_ordergg55s.pdf
    • http://dithetsen.xyz/74964242042sdtr6.pdf
    • http://fredo.bike/soul_train_awards_performances_2018hcjl8.pdf
    • http://salonapp.xyz/2736724906462ll2.pdf
    • http://ig-copyrightviolation.com/libro_juan_gabriel_y_yogslxj.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/novifamigot/foxconn_115xdbp_motherboard_drivers_download.pdf
    • https://s3.amazonaws.com/jenisozazewubo/24699591320.pdf
    • https://uploads.strikinglycdn.com/files/ab5de794-2ea5-4c0d-93cd-a3f6fbe0ed37/67169550237.pdf
    • https://s3.amazonaws.com/tutasujal/tezazirumepufovakubinu.pdf
    • https://s3.amazonaws.com/juvosi/belumaxozezezuveda.pdf
    • https://uploads.strikinglycdn.com/files/c0768dcb-bfe4-499c-b940-f59f98cc81b2/kimupotufawupezemixowopex.pdf
    • https://s3.amazonaws.com/sogovekevi/86781126260.pdf
    • https://uploads.strikinglycdn.com/files/97080ba4-dc94-42d5-852b-3a68ec9161f4/what_is_the_main_difference_between_paraphrasing_and_summarizing.pdf
    • https://s3.amazonaws.com/fenatagazise/xosamobim.pdf
    • https://s3.amazonaws.com/ragejufa/ti-30xa_solar_manual.pdf
    • https://s3.amazonaws.com/zamemigojat/article_format_spm_2018.pdf
    • https://s3.amazonaws.com/xisakazelelinim/28240374430.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011fa3.bin
85cd40fff9cc7db1971c11890bd062dd42d0d2dc65f037c2b59f02d2f47e0375
pdf-font-stream PDF embedded font (sfnt) at offset 0x11FA3 5220 bytes
font_01_sfnt_off00013152.bin
df1610d0db7fbe50a45484020db699b9cf6598581616a2bbf06fcd767d1c4e0e
pdf-font-stream PDF embedded font (sfnt) at offset 0x13152 10736 bytes