Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf832a42fcc527fd…

MALICIOUS

PDF

278.2 KB Created: 2021-03-15 02:58:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: d1d2e4eb548df1ef8608dd8a4c87acdf SHA-1: 839c239e753a28b383916e578bc7337c284bf5c0 SHA-256: bf832a42fcc527fd7dca22307fa881241285ccf5243bf0e17e71f46fe76aadb3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9890

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=nevada+medical+jurisprudence+exam+answers PDF link annotation
    • http://josumewemuzob.getenjoyment.net/88553901735.pdfIn PDF document text
    • http://fegiroxopirez.sportsontheweb.net/37498072600.pdfIn PDF document text
    • http://tozofuji.scienceontheweb.net/16084552610.pdfIn PDF document text
    • http://zuduwamani.mypressonline.com/11058480397.pdfIn PDF document text
    • https://nolelagisumo.weebly.com/uploads/1/3/4/1/134132353/sowujedirof_muwimuwijefifu.pdfIn PDF document text
    • https://lopamazaveseku.weebly.com/uploads/1/3/4/6/134643240/014a316a5c72a1.pdfIn PDF document text
    • https://gijufonuvaxi.weebly.com/uploads/1/3/4/8/134874477/8176f48d51.pdfIn PDF document text
    • http://doxalasi.mywebcommunity.org/zefor.pdfIn PDF document text
    • http://jakusavu.sportsontheweb.net/mercedes_eqc_preisliste.pdfIn PDF document text
    • https://wupupuredizuso.weebly.com/uploads/1/3/4/8/134894828/9311270.pdfIn PDF document text
    • http://lotobajigufar.mywebcommunity.org/93917492355.pdfIn PDF document text
    • http://mitatizizuje.mypressonline.com/rurogigogimemade.pdfIn PDF document text
    • http://madawuboso.sportsontheweb.net/ancient_greek_democracy_lesson_ks2.pdfIn PDF document text
    • https://lusimijibujadex.weebly.com/uploads/1/3/4/6/134677052/1322857.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/69e70769-2d13-4065-8395-4c67a10feebb/what_are_the_effects_of_human_activities_on_environment.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ea8f2de2-0574-4b20-ae25-80943b08234b/sinizajakipapojemu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/12f8552c-6b24-4f7d-9ffe-fcffd475765d/tototikep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/38aa3bdf-5139-4cd4-9a4c-9f3f7422500f/wunder_von_bern_netflix.pdfIn PDF document text
    • https://s3.amazonaws.com/vofadoloves/cadence_of_hyrule_ost.pdfIn PDF document text
    • https://s3.amazonaws.com/tugumeb/average_speed_4g_network.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9f1948b4-e513-4a26-bd3f-00e1f9bcbb9a/fogipavobazawoxa.pdfIn PDF document text
    • https://s3.amazonaws.com/vidadaviwal/instagram_report_impersonation_account.pdfIn PDF document text
    • http://gegetebipa.atwebpages.com/argumentative_essay_about_smoking.pdfIn PDF document text
    • https://s3.amazonaws.com/gebukil/65577964032.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004103e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4103E 5484 bytes
SHA-256: 73e62b3c8691781c68b0a6af87de59868ef2157d5017198e84c52eb84ab3ec80
font_01_sfnt_off000422ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x422EC 11416 bytes
SHA-256: 6871e77cd0d792b9d0aac8dff3f06f56758a2e90c53e480f6322e48bcd130d9c