Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8720164f73b6f8d…

MALICIOUS

PDF

38.7 KB Created: 2021-08-16 11:21:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.12.8)
MD5: 1497ae48fdd7fdb2667c390b2a5deaa8 SHA-1: e8f71b120add97d63c529d99b1b207c9ff93f5b0 SHA-256: c8720164f73b6f8d35bb6d0c0e834dcad0fa10335df3c2a0225814496bc82197
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The PDF document contains a direct link to a ZIP archive, identified by the PDF_DIRECT_PAYLOAD_LINK heuristic. This indicates an attempt to trick the user into downloading and executing a malicious payload. The URL points to a potentially malicious ZIP file, which is the primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier clean score 0.0015

Heuristics 2

  • PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINK
    PDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cld.pt/dl/download/4e094d48-7d64-4993-bbbe-1a16561e4753/sapotransfer-5c9a9a702f207x7/PDF.zip?download=true
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b37.bin
96506314c2c3a41383be2af940bb6f34cff402b9393dc0f712d3f4f67619d284
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B37 11408 bytes
font_01_sfnt_off00007596.bin
3f74c7b77625da7875edb47ee6113124f408cfd5216347c59cb66068bec21000
pdf-font-stream PDF embedded font (sfnt) at offset 0x7596 14632 bytes