Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3eb38cf793c2608…

MALICIOUS

PDF

24.8 KB Created: 2024-08-20 15:01:47 -06:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 5.15.3)
MD5: 04a755b6f29366b1edfb54033d5c49ae SHA-1: 615ed1b9ad7942c2c43ac4abee83b5bc320f4fd1 SHA-256: c3eb38cf793c2608f316262ce31d80c3013cbd0b55d36972afdee3ef9257bdda
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The PDF file contains a direct link to an executable payload, identified by the PDF_DIRECT_PAYLOAD_LINK heuristic. The embedded URL points to a file named 'setup-qtox-x86_64-release.exe', which is likely a lure to trick the user into downloading and running malware. No scripts were extracted, and the document body was unreadable, but the direct payload link is a strong indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier clean score 0.0155

Heuristics 2

  • PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINK
    PDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://github.com/qTox/qTox/releases/download/v1.17.6/setup-qtox-x86_64-release.exe

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00001c99.bin
c55552675356dba83b0c503968be1b309ec75bb92fcfc88dcf6ba72f496290d2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C99 12292 bytes
font_01_sfnt_off000039b1.bin
0a224902da875fa6989b9d25aa58179e14bfcee37c1f5bac75214721c865db86
pdf-font-stream PDF embedded font (sfnt) at offset 0x39B1 15536 bytes