Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4f46d0b7223ee91…

MALICIOUS

PDF

234.0 KB Created: 2021-03-26 18:33:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bf17802c5a2ff26e02b57a4ce6d761cb SHA-1: 9d3eba82a28a179063b7a355f8b257d661591d82 SHA-256: c4f46d0b7223ee9185aa4b70ff1c64a8c5cac4a8bd81bf3a8805f5dbb10797c2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, identified as a phishing attempt. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URL likely leads to a malicious site designed to exploit the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9838

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=the+medieval+history+of+iran+afghanistan+and+central+asia+pdf
    • https://cdn.sqhk.co/mudinaxape/dzhiNja/simple_birthday_cake_decoration_ideas_at_home.pdf
    • http://wodekenizowa.getenjoyment.net/how_to_do_a_semiotic_analysis_of_a_film.pdf
    • http://negedibomul.sportsontheweb.net/farisevemuguwesalubizu.pdf
    • https://cdn.sqhk.co/zimuvipejo/dUKijgf/zezutaredogavamolirutuful.pdf
    • http://duwefazef.22web.org/salesforce_default_approval_email_template.pdf
    • http://jevafurevozu.mygamesonline.org/lukudekizulelelamomupaju.pdf
    • https://cdn.sqhk.co/libobivole/EigeK3v/75602464372.pdf
    • https://cdn.sqhk.co/gamakokub/iNgjgcw/butimububeli.pdf
    • http://ledozikatiresev.scienceontheweb.net/how_to_call_with_fake_caller_id.pdf
    • https://cdn.sqhk.co/wenewojufaj/jfjfShb/44637420119.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://jovukanuwu.rf.gd/vafiwesudazeronuf.pdf
    • https://uploads.strikinglycdn.com/files/b5b99575-981b-43ce-86c2-fa8679eca7a4/john_deere_lawn_tractor_l100_parts.pdf
    • https://s3.amazonaws.com/mubefula/sazevu.pdf
    • https://uploads.strikinglycdn.com/files/a7095a5d-166d-4ebf-a240-89b3286468c6/nozidifux.pdf
    • http://fufezexu.epizy.com/fuvojimezikimasusojel.pdf
    • https://s3.amazonaws.com/xujitezu/venifis.pdf
    • https://uploads.strikinglycdn.com/files/ee85db73-2e7d-4ced-89c5-df1c47fd3df0/honda_6500_generator_for_sale.pdf
    • http://sedoguzod.rf.gd/bayesian_statistics_example_in_r.pdf
    • https://s3.amazonaws.com/donukadizolin/17794728289.pdf
    • https://s3.amazonaws.com/zuniverijesud/ruvaxebolowobonadatezu.pdf
    • http://nununad.myartsonline.com/jakemekopilog.pdf
    • https://uploads.strikinglycdn.com/files/a592f23a-d8cc-4ff6-b35a-da0f606fdfaa/how_to_use_adobe_draw_on_ipad.pdf
    • https://uploads.strikinglycdn.com/files/a7c55886-719a-4b72-8ada-97296b311f1f/43054915444.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off00036ad9.bin
98cef23f08e346ec79c5ab6c3a7ce6dce36d8a52237002486be920b06033637e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x36AD9 26144 bytes
font_00_sfnt_off0002eef9.bin
c6c0366a4f28e70031a7cfba9f1cda38e33f16ccd0a85cfa8b8f561398bc116d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EEF9 16588 bytes
font_01_sfnt_off0003236b.bin
d6b6acc84787c68cc7edc37dcc5f613c74a8c6489aefe84f5487b900e5610a03
pdf-font-stream PDF embedded font (sfnt) at offset 0x3236B 5680 bytes
font_02_sfnt_off000336a0.bin
af6a4820162bd324bcbc873f31cc5fc64d8fe60e78b54c97cd20b82895d6291c
pdf-font-stream PDF embedded font (sfnt) at offset 0x336A0 17564 bytes