Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd762c2ceec884b6…

MALICIOUS

PDF

87.0 KB Created: 2021-03-10 16:22:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cd68c5b4ddb9648fa8fd9923309a25bd SHA-1: aedaf434c577197582274b1ecc6c647dea804a62 SHA-256: bd762c2ceec884b67f7238565d3b364b54bf7cf086a06de8548ce79a557a047c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that points to a suspicious domain, identified by heuristics as a potential phishing or malicious link. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to redirect users to a site for further exploitation or credential harvesting. No scripts were extracted, but the presence of the malicious URL is sufficient evidence for a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=guide+digimon+world+3
    • http://trickyturkey.com/suppress_definition_antonymbp3sd.pdf
    • http://fezelegafefuv.mywebcommunity.org/felelogixunadefuz.pdf
    • http://rubyshup.space/rerosemfuoez.pdf
    • https://cdn.sqhk.co/xonipavu/fggN3qI/sewanafiw.pdf
    • http://todayshop.website/56834149231yj5sy.pdf
    • http://kajipim.mypressonline.com/moleki.pdf
    • https://cdn.sqhk.co/gogerazina/5gjCBge/bumenewalimanisuku.pdf
    • https://cdn.sqhk.co/xubuzivo/P9igqCB/xatebifava.pdf
    • http://seweripuwas.mywebcommunity.org/pemima.pdf
    • http://optamorem.com/95671563422v6rnc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://52468903-0e2d-47c5-babb-61e1d305d291.filesusr.com/ugd/32777b_5e3669980ad0462e97f9493cd03ab5d2.pdf?index=true
    • https://56db2a4d-09ce-4ff6-a558-abb1d6727cd4.filesusr.com/ugd/003b86_cd804382ec7346348d0d4b2cdef2cf6c.pdf?index=true
    • https://s3.amazonaws.com/kumasala/gadesebimoterowuzafuj.pdf
    • https://s3.amazonaws.com/gozifep/storyboarding_software_adobe.pdf
    • https://b3a8b944-ddec-4d17-9b53-5a1c05c66d8c.filesusr.com/ugd/314503_e84d6ef098a7471d88da519e7796e837.pdf?index=true
    • https://a179b4bb-f9e1-4b0b-8685-f881d2afde68.filesusr.com/ugd/0fdb6d_7353cc7949684853bc1125f8171406c1.pdf?index=true
    • https://s3.amazonaws.com/gazivemon/free_editable_chalkboard_invitation_template.pdf
    • http://bavatesivo.myartsonline.com/cuanto_dinero_se_puede_llevar_en_avion_a_estados_unidos_desde_ecuador.pdf
    • http://paguxesij.myartsonline.com/wozepunidazemusef.pdf
    • http://sogurorirerew.onlinewebshop.net/levunagomuriwig.pdf
    • https://3bdad275-8828-414d-9063-9532e035d791.filesusr.com/ugd/c67d0c_bdb5fe44d007492087a14127b2f33af3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec39.bin
2796196b374a8229df3d9fd2ecc25f17b376392b0fecce71495dbebc103eab27
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC39 14452 bytes
font_01_sfnt_off00011a67.bin
60eab276d4c4350f63454f4acd3909282e110318197a432d16b77212b912d673
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A67 5044 bytes
font_02_sfnt_off00012b95.bin
8f3fcd95acd9ee5b493b63478ecf539149c63247fd276c1281e88ee468ae71b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x12B95 10152 bytes