Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdf005ccb345f4ce…

MALICIOUS

PDF

96.9 KB Created: 2021-04-01 05:50:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 00b9ee0c208555d32ba48d72b4e29674 SHA-1: 822286a109f1c0d770de33588463c72ad36eeafb SHA-256: bdf005ccb345f4cea5453d890ac1000bb15c399b2b2ac1b6b16a09592f141ddb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI that redirects to a URL associated with a trigonometry worksheet, likely a lure. The ML classifier and ClamAV detection strongly indicate maliciousness. The presence of multiple embedded URLs, some with unknown reputation, suggests this PDF is designed to redirect users to malicious content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=chapter+8+right+triangles+and+trigonometry+worksheet+answers
    • https://sapigufebo.weebly.com/uploads/1/3/4/5/134592603/pidamu.pdf
    • http://daliadiago.com/way_of_the_elements_monkf2ia2.pdf
    • https://cdn.sqhk.co/moxinivo/igjb5sH/64367827654.pdf
    • http://dk-inc.xyz/28417185760chtp9.pdf
    • http://presentinsta.site/rig_veda_sandhyavandanam_in_kannadavui2l.pdf
    • http://usacarins.com/jorefii51zv.pdf
    • https://cdn.sqhk.co/pegebatanuz/jdgi90D/22481853081.pdf
    • https://wivixape.weebly.com/uploads/1/3/4/8/134897282/1634b0f0ef63777.pdf
    • https://cdn.sqhk.co/vetipewalu/FhhmCZh/smashing_the_battle_mod_apk_free_download.pdf
    • http://trickyturkey.com/the_first_stage_of_the_french_revolution_was_marked_by_thehmzy4.pdf
    • https://cdn.sqhk.co/ruperodu/uPcjj5D/easy_thai_red_curry_tofu.pdf
    • http://pekuxareja.22web.org/cancer_de_mama_definicion.pdf
    • http://vutajupej.iblogger.org/structure_of_beta_carotene.pdf
    • https://xovelojedawoka.weebly.com/uploads/1/3/4/6/134662979/2864482.pdf
    • https://dabesego.weebly.com/uploads/1/3/2/7/132740865/xelaza_fumejagokezev_gajeliwejowu.pdf
    • http://kasiwewevono.iblogger.org/7489778399.pdf
    • https://wabalolosezuluf.weebly.com/uploads/1/3/4/4/134462862/7919827.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://posopikepikan.rf.gd/speak_the_graphic_novel_by_laurie_halse_anderson_and_emily_carroll.pdf
    • http://xotujulenibol.epizy.com/abaqus_theory_manual_6._13.pdf
    • http://jitemawuvefogox.epizy.com/what_grimoire_does_julius_have.pdf
    • http://jogisav.epizy.com/petusibakamew.pdf
    • http://zewuxulaza.rf.gd/adobe_photoshop_7._0_tutorials_in_marathi.pdf
    • http://roxugotosaka.epizy.com/wavegenivabugasi.pdf
    • http://xoxepilazif.rf.gd/78290512898.pdf
    • http://zewipurorafe.epizy.com/16404097051.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013a22.bin
0e764d5154412fdd6738574f16e7d293fd88dd52f1bd04dbd9d9838ed74c6359
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A22 5732 bytes
font_01_sfnt_off00014d85.bin
445e4999b7a1ef74ed20dc2c0102df86807b4982f8b1db85b01f2dc83a6590e2
pdf-font-stream PDF embedded font (sfnt) at offset 0x14D85 12164 bytes