Malicious PDF — malware analysis report

Static analysis result for SHA-256 c66fe2c66aaae2b0…

MALICIOUS

PDF

76.7 KB Created: 2021-02-20 01:46:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: f71ee782a1f88180a009c6fa3f6bf58a SHA-1: 2331b9c62ac00060129acebb761fb3506195d6cb SHA-256: c66fe2c66aaae2b0e11a9da4ba6ca77192b306bf42ce5d795d5e9858f368137c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to a suspicious domain, likely intended for phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, potentially exploiting PDF vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=warrior+cats+movie+release+date+2023 PDF link annotation
    • https://cdn.sqhk.co/xamitarerivu/YEjgMr1/football_manager_2020_touch_inter_miami.pdfIn PDF document text
    • https://cdn.sqhk.co/vimexuda/h9d9Rif/bedwars_server_address_java_edition.pdfIn PDF document text
    • https://cdn.sqhk.co/pedidagow/iwiUijk/wibib.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4427295/normal_601b3984050c0.pdfIn PDF document text
    • http://ledy66.net/maitriser_excel_2010udann.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374199/normal_6023f4d0dea19.pdfIn PDF document text
    • http://lovelid.xyz/wrong_turn_2_dead_end_parents_guideasusl.pdfIn PDF document text
    • http://detolenikalopaj.iblogger.org/indiana_university_wall_street_journal_ranking.pdfIn PDF document text
    • http://zepawagir.iblogger.org/chicken_egg_color_guide.pdfIn PDF document text
    • http://digogipexoluku.iblogger.org/80935651179.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fevobelijogal/bihar_board_10th_marksheet_2013.pdfIn PDF document text
    • https://s3.amazonaws.com/xozeb/definition_of_protected_areas.pdfIn PDF document text
    • http://xovafufu.rf.gd/mass_haul_diagram_calculation_example.pdfIn PDF document text
    • https://s3.amazonaws.com/ninazarila/nivupidosabezufawisiv.pdfIn PDF document text
    • https://s3.amazonaws.com/wajibile/461543727.pdfIn PDF document text
    • https://s3.amazonaws.com/purixifusipelid/sikikenifulizanid.pdfIn PDF document text
    • https://s3.amazonaws.com/memobofilenabon/does_vizio_tv_have_a_reset_button.pdfIn PDF document text
    • https://s3.amazonaws.com/temujonuwu/weather_report_for_galena_illinois.pdfIn PDF document text
    • http://daduzafez.epizy.com/25206068517.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec90.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC90 5596 bytes
SHA-256: eabc21187b9e8db2dd93c645e06addabea29c839ea69382cc0956eadbb2fdc54
font_01_sfnt_off0000ff91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF91 10936 bytes
SHA-256: d4596b02e3a655011fed2662031a71890cb9ae8e682085fb6bca4d415b01a7b7