Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc2409c05e8a4a95…

MALICIOUS

PDF

98.1 KB Created: 2021-07-16 08:11:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 19b1ada8f7d77eed0eac7ee4604aa4fb SHA-1: 60b50a7445b51ee896899963f0d3c477571808da SHA-256: cc2409c05e8a4a95f94a8ef005c9d42c4e39e7bb975c1ce5db6e3f32bfa5f24e
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains an embedded URL pointing to a domain associated with cracked software, indicating a phishing or malware distribution attempt. ClamAV detection and ML classification further support its malicious nature. The document body, though heavily obfuscated, likely contains the lure to encourage clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5879

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://infrive.ru/square?utm_term=autocad+lt+2017+serial+number+and+product+key+crack
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f056930b1da83e5094ca58/1626363539151/manexa.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f0c1f51f3fa43bb6b36155/1626391029504/92839762102.pdf
    • https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60e8fe99b9b95949b65d3a70/1625882265732/high_volume_video_player_for_pc.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8bd3f3601b306b46f6537/1625865535696/64569917166.pdf
    • https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60ecb763522a83061659238c/1626126179384/hubers_orchard_and_winery.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ecf2a967dd777ebfbb1ebe/1626141354058/54463262626.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00010dec.bin
9f0c496fa061b75ac39025886a334c97334507be8ef53c0cf3b32371f1ea4a28
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10DEC 20740 bytes
font_00_sfnt_off0000f2ef.bin
0da08d6e8b810f547a01a66a80ac61586ae63aba49512df30de94b73aa0e04ac
pdf-font-stream PDF embedded font (sfnt) at offset 0xF2EF 11448 bytes
font_02_sfnt_off00013158.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x13158 16792 bytes
font_03_sfnt_off0001496a.bin
da290b02f47632e7a98211d5bba4479b2a0809dd9267a8378cabf8dc2e12a499
pdf-font-stream PDF embedded font (sfnt) at offset 0x1496A 18580 bytes