Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf81d0b1b572395e…

MALICIOUS

PDF

194.0 KB Created: 2021-03-20 12:40:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b9e35b892bfe9f343c722670a08cb930 SHA-1: bccaade255cecb92df459afeea7aad0efbaecc92 SHA-256: bf81d0b1b572395ec9ccf212431ac41d6cfa8db62ddcaaa6ccff21ee87bdef37
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that redirects to a page seemingly offering product information, likely a lure for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to exploit vulnerabilities or trick users into navigating to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=apple+macbook+pro+a1278+year
    • https://cdn.sqhk.co/zotiperugi/5Jgd7hf/spongebob_kart_racers_xbox_one.pdf
    • http://getcabinets.xyz/what_type_of_organizational_structure_is_niketmkvg.pdf
    • https://cdn.sqhk.co/molewekane/iFP0geH/herpes_simplex_keratitis_treatment.pdf
    • http://xovasaf.iblogger.org/24019953782.pdf
    • http://odebayitrafikhizmeti.com/academic_writing_formathwzu8.pdf
    • https://cdn.sqhk.co/sobetevod/Sjcieig/obdeleven_car_diagnostics_v0._16._2.pdf
    • http://copyrightsafetyhelps.com/befotuloptlwcw.pdf
    • https://cdn.sqhk.co/kuzaxepigi/geLDheO/nofifavaniv.pdf
    • http://blankid.ru/18222643654n396f.pdf
    • http://copyrightmediahelp.com/denoveropadoxewukubuxezy2htv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fikikozazilut.rf.gd/talufelezobujegukubu.pdf
    • https://1261df91-4e32-40b2-8b8a-4050d3c54cbb.filesusr.com/ugd/df69c1_4c87db1de1f941608810247166a1690d.pdf?index=true
    • http://fogivezin.rf.gd/what_is_developmental_and_life_course_theories_of_crime.pdf
    • https://uploads.strikinglycdn.com/files/280655e7-65c8-490a-befc-b959b43e3037/kaludemukatemovufiwobisa.pdf
    • http://gomupinoteripa.epizy.com/39953796100.pdf
    • http://jezutax.rf.gd/chaalbaaz_hd_movie_free.pdf
    • http://biborufa.epizy.com/migagedezafifonovumove.pdf
    • https://uploads.strikinglycdn.com/files/ee7bbb40-a95b-4f0e-9b50-f73edfc86b9a/omron_blood_pressure_monitor_hem-432cn2.pdf
    • http://mesuwepuru.epizy.com/bikopuribovupiwuwozasemid.pdf
    • http://labopum.rf.gd/greatest_common_factor_worksheet_with_answer_key.pdf
    • https://eb72eaa1-ef55-40a3-a653-f6d21bccf295.filesusr.com/ugd/54913d_90cb80aecfb4417dbca6ab2e7d21a705.pdf?index=true
    • https://uploads.strikinglycdn.com/files/de54eb14-69b6-417a-8698-b12081484040/80758209085.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002a683.bin
a4e738a5dcc02eb0939adf7d402ede609f37b9959f05be548785012d84deff0c
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A683 5652 bytes
font_01_sfnt_off0002b9c1.bin
0f7e94060209efc2b5fbaa8e18f7d1fc08f4ce329c22bd0b1f0b3c4ea9a8b0be
pdf-font-stream PDF embedded font (sfnt) at offset 0x2B9C1 12844 bytes
font_02_sfnt_off0002e5bb.bin
e8220701f4abc5c2578c6b81392a5eb74511f2628282971200dd586ef0f811f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x2E5BB 16072 bytes