Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3e9c0ce5657de89…

MALICIOUS

PDF

73.4 KB Created: 2021-06-01 05:09:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dd6f942f9c938e58e1a9f8bbb6f47ee2 SHA-1: 1cbc89974bb0dededf709d5b5d09010170f3d839 SHA-256: c3e9c0ce5657de89400a4281c8890a396ef429fc011d63649903bfb51af632e6
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The PDF contains embedded URLs that likely lead to further malicious content or phishing sites. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to trick users into downloading or interacting with malicious content, aligning with spearphishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9316

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://worldkelo.com/wp-content/plugins/super-forms/uploads/php/files/a836b321059d8b7f58cf78220d32995a/wojusefizu.pdf
    • https://www.pfgpartners.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160a412eb78a0e---kuxadupasixorozoluxu.pdf
    • http://becro-plast.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1606d9f44564d5---76377821288.pdf
    • https://www.ideaklinikankara.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074fd2e2e9b5---6358249396.pdf
    • https://jclifeschools.org/wp-content/plugins/super-forms/uploads/php/files/f80d9d52de9497dfb81b3b53851938e8/1947109919.pdf
    • http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/cbbbf9b014ac8c8d480c50b05e0476af/43724986435.pdf
    • http://kindervakantieweekdeurne.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160a7fa697e49d---diparunanegudifobalobexe.pdf
    • https://stagerightstaging.com/wp-content/plugins/super-forms/uploads/php/files/bbbaf9ecd4209d293b4d6e2461b9d0f7/runilezeronogufanon.pdf
    • https://www.sanier.pl/wp-content/plugins/super-forms/uploads/php/files/s0mu79h9qdkm295c4pohoil65o/18657332612.pdf
    • https://storage-in-motion.com/wp-content/plugins/formcraft/file-upload/server/content/files/160adcd29a1d6d---nepunugejasapexuwap.pdf
    • http://apexhealthnutrition.com/newerac2c/userfiles/file/kurinu.pdf
    • https://www.nobleorthodontic.com/wp-content/plugins/super-forms/uploads/php/files/3342822cc95c86c4c66303664c756ef1/xaren.pdf
    • http://www.a-fairys-choice.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a887be74c73---71565151512.pdf
    • https://coachtourbusrental.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b56a839d8f5---27283988853.pdf
    • https://maugli24.ru/wp-content/plugins/super-forms/uploads/php/files/35ba139cc37f893f50319abd7a083c57/87452183971.pdf
    • https://www.onestopnaturalstore.ca/wp-content/plugins/super-forms/uploads/php/files/646ejogjq7lf5v6iu2m2n2gvlq/84201497430.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/LPIa9PGmDLg/uplcv?utm_term=introduction+to+elementary+particles+david+griffiths+pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9aa.bin
41aa9585c3d55af8b5c99b80614e4487a63062309ff2bfde36a3b6d4bf1baa99
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9AA 5552 bytes
font_01_sfnt_off0000fc64.bin
59cf2ebd76664a05c48caf7050b0a5b11a2ef1444f70e96fdb74addf0b216f20
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC64 10564 bytes