Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdd66561e7ab042e…

MALICIOUS

PDF

81.6 KB Created: 2021-04-05 23:58:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f8bb225b601e255c0bf3a4f19de5410d SHA-1: 92b74dc34a6cd8dac56ade1bd2efe71379d3c704 SHA-256: bdd66561e7ab042e2d5070d9ca31c0f2b03c248fe6e8b7c5fde83972c0936717
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into downloading a malicious payload or visiting a phishing site. The document body, though heavily obfuscated, suggests a lure related to educational content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/award?keyword=elementary+algebra+questions+and+answers+pdf
    • https://cdn-cms.f-static.net/uploads/4375703/normal_5fd9647cc6642.pdf
    • https://cdn.sqhk.co/sebutarukaw/gd3vggW/top_100_coolest_cars_in_the_world.pdf
    • https://static.s123-cdn-static.com/uploads/4419191/normal_5ff8c7a268088.pdf
    • https://cdn.sqhk.co/belebudetub/PjaDCgg/world_war_1_timeline_activity.pdf
    • http://trokot-tonirovka.online/86971630599qxh6d.pdf
    • https://cdn.sqhk.co/nakunadubux/jsihw8E/99919614087.pdf
    • http://s7hmus.org/nalurugujixegeltu5pe.pdf
    • https://cdn.sqhk.co/letinumi/va4gdlH/funny_racing_memes.pdf
    • http://virnet77.ru/standoff_2_apk_mod_money_0._10._11x4ll2.pdf
    • https://cdn-cms.f-static.net/uploads/4424025/normal_60174e273ba9d.pdf
    • http://lnstgramhelpcopyright.com/84181329262kfqix.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/04180513-973d-48be-8333-3eef8ad4a890/how_to_disengage_hydrostatic_transmission_john_deere_zero_turn.pdf
    • https://uploads.strikinglycdn.com/files/dba54faa-81f6-43f2-b55f-004f300658e8/the_green_mile_book_chapter_summaries.pdf
    • https://ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com/ugd/eda9ba_40fca80680ac4d8a8df6df3d870ac0aa.pdf?index=true
    • https://50aad03f-9d2a-47e6-be13-abd12f321b17.filesusr.com/ugd/3fd638_5f418aa4d0ce4a70970ed1ca373ae565.pdf?index=true
    • https://2f8a6ab9-e864-4757-b083-6627a13f4c48.filesusr.com/ugd/405339_96ab5b4db99a451ebb2c6b8072fbc371.pdf?index=true
    • https://uploads.strikinglycdn.com/files/98826f10-867b-41cc-ae75-79a437e5c4e1/74077358818.pdf
    • https://uploads.strikinglycdn.com/files/fe896e7a-a3f6-49a9-bd44-6130a0f7c85b/rizubiruzulara.pdf
    • http://bavidoripo.epizy.com/english_for_aviation_oxford.pdf
    • http://jufowepazo.rf.gd/208242124.pdf
    • https://uploads.strikinglycdn.com/files/58850a21-11ec-42fd-8375-c15be2266dba/storyboard_template.pdf
    • http://kavaxix.rf.gd/deworubajaretewuwawep.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f201.bin
613069afeda1a896ba0167e6399b587afd740c1e1743cc9c78e4ae8dd95c7282
pdf-font-stream PDF embedded font (sfnt) at offset 0xF201 5660 bytes
font_01_sfnt_off0001052e.bin
c841eeac90a0da90bc20edf4f401b6a3f245ed4ddc9658e14e234c9d4681566c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1052E 10932 bytes
font_02_sfnt_off00012a51.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A51 4324 bytes