Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2adfa6a0bc58812…

MALICIOUS

PDF

68.0 KB Created: 2021-04-14 21:50:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 0e135bb500fd18efe3d22507bc20fbe4 SHA-1: 1cdf63c6dec61b2cb3f8667b932fe51d3090a28c SHA-256: c2adfa6a0bc5881205ea041b6c04bdedaba6b278db032e6e6e36f2b746f492c0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The PDF contains embedded URIs that likely lead to phishing or malware distribution sites. While no scripts were explicitly extracted, the presence of embedded URIs and the nature of the ClamAV detection (Pdf.Phishing.Trojan) strongly suggest a phishing or credential harvesting attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cicatsalud.com/html/sites/default/files/webform/sidetarebuw.pdf In PDF document text
    • https://ambrose.edu/sites/default/files/webform/82598578892.pdfIn PDF document text
    • http://russian-ice-spb.ru/sites/default/files/webform/files/77599308563.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/20598750849.pdfIn PDF document text
    • https://web.liderpapel.com/sites/default/files/webform/dojoxopanikofogenag.pdfIn PDF document text
    • https://www.ofalloncasting.com/sites/default/files/webform/taxebuvokorutupimapo.pdfIn PDF document text
    • https://www.jts.org.jo/sites/default/files/webform/1653940235.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/61928937085.pdfIn PDF document text
    • https://ambrose.edu/sites/default/files/webform/59680287402.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://feedproxy.google.com/~r/skout/mBVl/~3/GLLx1DTH0VQ/uplcv?utm_term=intel%2528r%2529+82865g+graphics+controllerPDF link annotation
    • https://minorsoncampus.princeton.edu/system/files/webform/vogifowisawab.pdfIn PDF document text
    • https://www.healthdata.org/sites/default/files/resumes/mevupuxapiledowitire.pdfIn PDF document text
    • https://ec.europa.eu/eip/agriculture/sites/default/files/webform/sukazejaso.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cba5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCBA5 5892 bytes
SHA-256: df15661c6d42e083ed0995a103c688bb62a19825d56f2b3a6a030671809ebd71
font_01_sfnt_off0000dfbd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDFBD 10452 bytes
SHA-256: f46a66be6f7100322c38b26dcc92e61ce88ab51f396c2b0a36e93ffd13e94dd3