Malicious PDF — malware analysis report

Static analysis result for SHA-256 c9324392615d827e…

MALICIOUS

PDF

73.2 KB Created: 2021-03-22 09:28:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1d3e3b5727b8de74a798a58aa4a64143 SHA-1: 08655309b80f7ec08ea51b7c87352d92b93d80a4 SHA-256: c9324392615d827e28e31bdb916051f350972e205ac58df7898749e0ab3a0cf7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for an external URI, pointing to a suspicious URL that appears to be a lure. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were extracted, the presence of the external URL suggests the document is designed to redirect the user to a malicious site, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=frigidaire+dehumidifier+50+pint+filter+reset
    • https://cdn.sqhk.co/kasunelebak/e1Gibjb/18099565565.pdf
    • https://cdn.sqhk.co/penuvipaw/kNijNk8/13240447125.pdf
    • https://vesukinixemijuw.weebly.com/uploads/1/3/2/6/132696016/8b88ba374e75e.pdf
    • https://digutejuwunapon.weebly.com/uploads/1/3/5/3/135325267/kabebejatigub_mapaxulidid_mabixunejofunuf_kufefaxiratavo.pdf
    • https://xujopikaxatanow.weebly.com/uploads/1/3/4/8/134850499/6406949.pdf
    • https://cdn.sqhk.co/fovipobex/jgfjbg1/scrum_daily_standup_template.pdf
    • http://gexaxevapoxi.iblogger.org/what_is_my_management_style_test.pdf
    • http://italiahot.space/jogiwisoun7p2.pdf
    • http://joy-todays.online/jivemodugatowatuxuladi49za.pdf
    • http://indir-kazan.com/injustice_2_ps4_gameb6bqi.pdf
    • https://xatikofaf.weebly.com/uploads/1/3/0/8/130814669/pibomo-dubewisuwufigep.pdf
    • http://razvivatel.blog/166432809bb0ei.pdf
    • https://cdn.sqhk.co/livaxipovage/hsxJeih/dr_driving_city_2020_mod_apk.pdf
    • http://menesoger.iblogger.org/baxif.pdf
    • http://saxefitipar.iblogger.org/automatic_transmission_diagram.pdf
    • https://cdn.sqhk.co/wosuzumamig/hd9ghmf/good_street_racing_cars_for_beginners.pdf
    • https://vodemiteju.weebly.com/uploads/1/3/4/7/134722100/bukegagudowawuz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://notovagewalarin.epizy.com/41036133842.pdf
    • http://bopobirogugosef.epizy.com/33593178255.pdf
    • http://regujivabi.rf.gd/kotizazegigakex.pdf
    • http://ratazudawi.epizy.com/nonenuwi.pdf
    • http://mifinuxob.epizy.com/vibinipotajutiton.pdf
    • http://wijevisufa.rf.gd/surozog.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dcd4.bin
4ef04cd902a1996a003b5b16454539d0d68300f6b82822e6e11f0e7a4188ffca
pdf-font-stream PDF embedded font (sfnt) at offset 0xDCD4 5676 bytes
font_01_sfnt_off0000f000.bin
1d339d7d68fed500f35b92f463b340d27e4102488fc124a04ce62f2294ed386a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF000 10900 bytes