Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8bce30a9a8aa0f9…

MALICIOUS

PDF

76.4 KB Created: 2021-03-15 17:15:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: b41b932fa8a3598bd40e5b989328c11b SHA-1: c0df4f5b55fed0decdc681bc685d9980d9c8cfe0 SHA-256: c8bce30a9a8aa0f92b15c4e0f9b736fd3e4bfb12ff9212b993d55af1d72bed69
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=myopenmath+calculus+answer+key PDF link annotation
    • http://powakuvape.22web.org/rupiwulojegef.pdfIn PDF document text
    • https://cdn.sqhk.co/gulizate/ehdibgf/clash_of_mythos_best_heroes.pdfIn PDF document text
    • http://jatulusejeb.iblogger.org/xipobivinitomitafedinufo.pdfIn PDF document text
    • https://cdn.sqhk.co/momebuman/haiaiaY/king_s_college_london_business_management_ranking.pdfIn PDF document text
    • http://levupag.22web.org/their_eyes_were_watching_god_summary_chapter_2.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zomuzigo/98239082748.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1629dd6-e08b-4d6c-8ff7-1d2f09cb59d2/43992901852.pdfIn PDF document text
    • http://vabizofolimise.epizy.com/jejebenu.pdfIn PDF document text
    • https://s3.amazonaws.com/garorowa/molavoza.pdfIn PDF document text
    • http://podekorutad.rf.gd/aranesp_package_insert.pdfIn PDF document text
    • http://pugagewuda.rf.gd/29720365814.pdfIn PDF document text
    • https://s3.amazonaws.com/kotodur/30526047125.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7392141a-aa0c-403e-abdb-9c6eed7825c7/39804362886.pdfIn PDF document text
    • https://s3.amazonaws.com/xozeb/biomedical_waste_management_research.pdfIn PDF document text
    • http://zitejilid.epizy.com/83410822823.pdfIn PDF document text
    • http://juvokumepi.rf.gd/mount_everest_guide_service.pdfIn PDF document text
    • https://s3.amazonaws.com/pusolefosex/pharmacological_bioassay.pdfIn PDF document text
    • http://dutakewapil.epizy.com/market_leader_upper_intermediate_business_english_course_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/94b740ac-e7d9-4b34-81b4-f59d334b277f/41527114532.pdfIn PDF document text
    • https://s3.amazonaws.com/wajufifenoxuj/conceptual_physics_chapter_8_momentum_assessment_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/mivokozibu/muvesunafotixuviferuzuran.pdfIn PDF document text
    • http://lelekon.epizy.com/american_english_file_2_second_edition.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eccd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xECCD 5436 bytes
SHA-256: 2b41625ffd235fa5ac7320d3b612fd29580c52945b5d452e570b7af2fb6d1d24
font_01_sfnt_off0000ff42.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF42 11016 bytes
SHA-256: 45ce517c5547019ca91b807744d5a41288ef758474c962822b22fbfe6330a444