Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4270c6d8d2e234e…

MALICIOUS

PDF

87.6 KB Created: 2021-04-05 22:48:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e165b8e006d0d39d82954f62ebdd44bc SHA-1: 1377c953322cf477b273bd60da99d29d72d94905 SHA-256: c4270c6d8d2e234e88b79779ff41adda03a01572f777d3893a9d10710391b85e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded URLs that lead to suspicious domains, and the ML classifier strongly indicates maliciousness. The document body, though partially corrupted, contains text related to scientific articles, suggesting a lure to trick users into visiting these malicious links. The presence of external URIs and the ClamAV detection further support a phishing or malware distribution attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/123?utm_term=articulos+cientificos+pdf+scielo
    • http://zonitupupafof.sportsontheweb.net/8804875261.pdf
    • http://kotudekudoges.getenjoyment.net/sewuwipavujinegoxeta.pdf
    • http://ravovenovibu.medianewsonline.com/how_to_write_roman_number_100.pdf
    • http://zuvinesewuwiz.iblogger.org/which_nitrogenous_base_is_present_in_dna_but_not_rna.pdf
    • http://jotafitosixa.getenjoyment.net/adjective_plus_noun_exercises.pdf
    • http://boguzimaro.getenjoyment.net/jutevukizuxexi.pdf
    • http://femuxeririta.mygamesonline.org/konikofipanovazinirafib.pdf
    • http://vosojivaru.mypressonline.com/manual_de_epidemiologa_y_salud_pblica_panamericana.pdf
    • http://rasudilikid.mywebcommunity.org/how_to_reschedule_dmv_appointment.pdf
    • http://sewatumafuta.medianewsonline.com/ingenuity_inlighten_baby_swing_reviews.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c6f1ce88-b1be-476e-8591-c80b817d6a57/ilive_5.1_32_home_theater_system_with_bluetooth_ihtb138b_review.pdf
    • https://s3.amazonaws.com/tobovunoberiki/frases_programacion_neurolinguistica_para_nios.pdf
    • https://s3.amazonaws.com/minaxigevani/fundamentals_of_pathology_2021.pdf
    • https://c2963e02-5f2a-49ff-bb4d-22715b80ab3a.filesusr.com/ugd/55efe4_5d65e062d9f34280995f04db25b3d4a8.pdf?index=true
    • http://dunixojojulif.epizy.com/34756488601.pdf
    • http://rekabalukog.rf.gd/ashleigh_jordan.pdf
    • https://uploads.strikinglycdn.com/files/b703c5ef-0833-4ecd-a7a2-6ae123a52d2e/april_2021_new_moon_date.pdf
    • https://1c684d3d-b1aa-4d58-8f8e-408f9cf37fac.filesusr.com/ugd/64d889_c4e6cf33795a40e49dcfe100f9095873.pdf?index=true
    • https://uploads.strikinglycdn.com/files/be8b1ac2-9b3e-4015-82b3-f3f57f79288a/old_bridge_high_school_website.pdf
    • https://0a3c8164-ddd9-4522-8472-457ce31ece15.filesusr.com/ugd/d32f78_08899810f45e428692d2f8f4eeada4c9.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b353d301-cd82-4dc5-8353-d2c3f99ca43d/g_shock_ga_150mf_price.pdf
    • https://s3.amazonaws.com/wiwuxot/cisco_router_1941_datasheet.pdf
    • https://2e5cbe44-7de3-4e3f-b94c-8a8567814465.filesusr.com/ugd/f96b02_61c3bf3722244a5c9426493b3225abeb.pdf?index=true
    • https://s3.amazonaws.com/rimepusox/bcd_to_binary_conversion_in_8085.pdf
    • https://486a928f-df87-4682-b39c-9199637d78f9.filesusr.com/ugd/982a49_4ae3527323454c229ed95dd612ada79f.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011607.bin
cd649965f80f42f32a48ca11a2d0298bddb4ed6819c971eb06df0420ed122ab9
pdf-font-stream PDF embedded font (sfnt) at offset 0x11607 4928 bytes
font_01_sfnt_off000126e0.bin
34c11dc0a28be020b211d2ca4897d93cea44ba4ab917c488c2f33ce2734cf4ef
pdf-font-stream PDF embedded font (sfnt) at offset 0x126E0 13236 bytes