Malicious PDF — malware analysis report

Static analysis result for SHA-256 c282dc7fd6bdab82…

MALICIOUS

PDF

72.0 KB Created: 2021-03-16 05:38:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9388c52c9c27ec3aa8a4fb940b2e992e SHA-1: 953ce3f36d8640b209165735967dea9759a6c926 SHA-256: c282dc7fd6bdab8256d08b77a2656e3379cdcca1f594ab15b1839a0f9059f852
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded URLs, with the primary one being a lure for a study guide answer key. ClamAV and ML classifiers strongly indicate maliciousness, consistent with phishing or malware distribution. The presence of external URIs suggests the document is designed to redirect the user to a potentially harmful website.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=the+book+thief+study+guide+questions+answer+key
    • http://myluckywin.site/clave_para_activar_corel_draw_x6_grafw5pd.pdf
    • http://perevod-card2card24.site/how_to_charge_solar_watch_fastsyj2u.pdf
    • http://bodyita.space/3942066916maj5j.pdf
    • http://fenellalucynelle.info/caleffi_manual_air_ventyigu9.pdf
    • http://nafarami.medianewsonline.com/sovafuzuzosibema.pdf
    • http://nakezubelakibe.22web.org/diablo_3_season_15_barbarian_guide.pdf
    • http://wide-take.top/mtk_engineering_mode_guidenug52.pdf
    • http://bulakirip.getenjoyment.net/although_though_even_though_exercises.pdf
    • http://topcabinets.xyz/arteriovenous_malformation_embolizationqqinx.pdf
    • http://fodefon.getenjoyment.net/linksys_ea6500_v2_specs.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vetamedisoz/clinical_pharmacy_review.pdf
    • https://s3.amazonaws.com/domegagowevag/how_many_worksheets_can_excel_have.pdf
    • http://forojiwimudobo.atwebpages.com/critical_discourse_analysis_the_critical_study_of_language_fairclough.pdf
    • https://s3.amazonaws.com/wetevali/river_flows_in_you_guitar_tabs_songsterr.pdf
    • https://s3.amazonaws.com/xakajoziwibi/debenalekukagomubisates.pdf
    • https://s3.amazonaws.com/pobixedele/gefol.pdf
    • https://s3.amazonaws.com/vexosafugunu/irobot_roomba_discovery_4220.pdf
    • https://s3.amazonaws.com/xurixado/voluxubazuvulawad.pdf
    • https://s3.amazonaws.com/ginutu/ca_final_exam_date_sheet_nov_2019.pdf
    • http://difesasud.epizy.com/zawabodiv.pdf
    • https://s3.amazonaws.com/jumedemimo/click_your_heart.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dd97.bin
700fd65b44f1248d9813d72ad5eac8bcd73c402595155574eab6aa3ff300c2d3
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD97 5612 bytes
font_01_sfnt_off0000f0b2.bin
d6cada511e0c8c90155b8fb69979096e7fbb8998c9e39abe51664ff947bd6a64
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0B2 9828 bytes