Malicious PDF — malware analysis report

Static analysis result for SHA-256 c206d4c7a58a3a8e…

MALICIOUS

PDF

86.4 KB Created: 2021-02-21 23:54:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3112aa2c16584cd4abad03c68c7b61b1 SHA-1: bf755fcb0e2883f74ffa413fe9b05edd8c52eeb0 SHA-256: c206d4c7a58a3a8e1a87ac7f6475be5ec9adba6da5d3772583f9401b18874082
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an embedded URL that, when clicked, leads to a site offering an APK download. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. The presence of an external URI and embedded URLs points to an attempt to redirect the user to a malicious site, potentially for downloading further malware or for phishing purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=nova+launcher+prime+latest+apk+free
    • http://gaydating.world/tiwevinigarozf3uq.pdf
    • http://wipababotuzuke.iblogger.org/thinking_skills_worksheets_for_kindergarten.pdf
    • https://repotadidutu.weebly.com/uploads/1/3/4/3/134310826/maviwonut.pdf
    • http://cartest.pro/denibazawez5411p.pdf
    • http://verifedform.com/pifujedepkbji3.pdf
    • http://mabay.fun/pulizofujapaburepidimowo7cr95.pdf
    • https://xononegedu.weebly.com/uploads/1/3/0/7/130738921/wuwitigef_xovonisem.pdf
    • http://poverkavoda.website/nodiravobiw9q6d.pdf
    • https://gefatute.weebly.com/uploads/1/3/5/3/135345711/92d9216c2c.pdf
    • https://cdn.sqhk.co/rojarasam/LjbhjlX/modern_sofa_design_2020.pdf
    • http://glawerry.online/a_christmas_carol_full_story_by_charles_dickensojjih.pdf
    • http://dronextactical.xyz/respondent_answerer5foi2.pdf
    • https://cdn.sqhk.co/temirikuji/jcPkTgK/ww2_webquest_european_theatre_answers.pdf
    • http://salonlabs.xyz/wordly_wise_3000_book_11_fourth_edition_answer_key0iwe4.pdf
    • http://1xbet-registrat.site/nico_nico_video_online8hftt.pdf
    • http://f13x.xyz/globe_top_up_prepaid5vr0i.pdf
    • https://cdn.sqhk.co/joxutedunik/icifage/super_slime_sam_2020_poopsie.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f63c.bin
ccf9fb892202b4bb2088ce8142a4053323d469e40edb26319e9635fab615566c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF63C 3352 bytes
font_01_sfnt_off0001023c.bin
db940a27cd628f82ad6ac3a352528761efc1ac413d1a3c127ecd3df2ee2361f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1023C 5232 bytes
font_02_sfnt_off000113de.bin
9067b91751ab4a844d2f12e30d6b69f4d55440e0f3fb590d92bd683b6f89cfac
pdf-font-stream PDF embedded font (sfnt) at offset 0x113DE 13120 bytes
font_03_sfnt_off00013d90.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D90 4324 bytes