Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb33084e791d91b0…

MALICIOUS

PDF

77.1 KB Created: 2021-03-23 08:51:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7570cbb1bbb9fc275bbb63266c6803dd SHA-1: 141a4293624b54c5885777fcb99eae4a7298a07e SHA-256: cb33084e791d91b0c8855e20162589407f27941f5df956e8ba840f54ce754b37
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by a machine learning classifier and ClamAV, with a specific detection name indicating it is a phishing trojan. The PDF contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a malicious site. Although no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest it is designed to exploit users through deceptive content, aligning with phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=dieta+celiachia+pdf
    • https://cdn.sqhk.co/bizewavaxug/idihgc3/38067038399.pdf
    • https://cdn.sqhk.co/xaxovowupofa/IjePRqZ/microsoft_video_editor_windows_10_free_download.pdf
    • https://cdn.sqhk.co/zejejofe/geFNVkk/13082231544.pdf
    • http://fumumowovufa.mywebcommunity.org/class_12_cbse_chemistry_textbook.pdf
    • http://mojadejazisapa.sportsontheweb.net/project_management_hard_skills_resume.pdf
    • http://sodowetan.mywebcommunity.org/32281712082.pdf
    • http://netolenogafa.getenjoyment.net/calculate_the_centroid_of_the_shaded_area_with_respect_to_the_x-axis_and_to_the_y-axis.pdf
    • http://pifafixejizigu.scienceontheweb.net/78119437089.pdf
    • https://cdn.sqhk.co/nanubebebot/4hg3hai/34199083321.pdf
    • http://pozesex.iblogger.org/wudijujiwitekifasapuxokor.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vifusupegiza/5029790624.pdf
    • https://s3.amazonaws.com/legipalofi/13774661657.pdf
    • http://xemunebo.atwebpages.com/89199909170.pdf
    • http://wunilos.epizy.com/62505612560.pdf
    • http://nozozuwovore.atwebpages.com/wanotu.pdf
    • http://biwefejiza.myartsonline.com/arquitectura_de_software_libro.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef97.bin
2d7bd05aa3d8a5e53eb677eb3be777d7a84b41437fc5f92933d3f1db8ee36963
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF97 4968 bytes
font_01_sfnt_off0001008a.bin
a9150432770ae013b097292fd22a19d9bbaf974af4b6f2f1620501bdc7499a1a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1008A 11604 bytes