Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfa2b3799b7549d4…

MALICIOUS

PDF

78.9 KB Created: 2021-03-19 19:14:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b4ed55111c9712eb0f2ac9464e5992d2 SHA-1: 7ce091b246bd894a4ab15b4dbdbe01333a86ddc3 SHA-256: cfa2b3799b7549d480556c8a7704273625d797f3a7fc441e8ab181941f85e41d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of external URIs, including one pointing to 'golowaki.ru', suggests the document is part of a phishing or malware distribution scheme. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are commonly used to redirect users to malicious sites or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/wix?keyword=french+laundry+cookbook+pdf
    • https://cdn.sqhk.co/dezuvosowato/gegiNM6/11202180110.pdf
    • http://itravelgr.com/fifavoxekoraxwyjs4.pdf
    • https://cdn.sqhk.co/nupozifulija/frz1jc9/lbs_to_kg_nursing.pdf
    • http://playmarket-online.com/the_norton_anthology_of_modern_and_contemporary_poetry_3rd_editioni3dq0.pdf
    • http://adanakebap.org/lifubutirumify85mo.pdf
    • http://christinaanddavid2019.com/2118739530kd9af.pdf
    • http://ontrade.top/9293297858hv1x5.pdf
    • http://trysucre.pro/51127258551olqbo.pdf
    • https://kuduxuke.weebly.com/uploads/1/3/5/3/135323303/1129479.pdf
    • https://vakikuxikedeti.weebly.com/uploads/1/3/5/3/135320305/3029589.pdf
    • https://venevivoxeda.weebly.com/uploads/1/3/1/8/131857756/7417900.pdf
    • http://fitdieta.com/lixeruxesidaltdery.pdf
    • https://jakineporop.weebly.com/uploads/1/3/5/3/135302356/pijivaner-lokebanowojuru.pdf
    • http://copyrightreports.com/66785293502k8dyd.pdf
    • http://ing-cliente.com/declaracin_universal_de_los_derechos_humanos_ecuadors4p5c.pdf
    • https://tofavasexivefet.weebly.com/uploads/1/3/4/5/134578877/5062753.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/pegebunov/isth_guidelines_hemophilia.pdf
    • https://s3.amazonaws.com/pajukovuxetu/tewubozi.pdf
    • https://s3.amazonaws.com/dalava/mamakaregozawobenagafufod.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f677.bin
e7eaf36c2cd5cfd2c0cee7088e501fd4b5c5217765d4b311214a3b876558718f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF677 5324 bytes
font_01_sfnt_off00010898.bin
e8f2459eb42ba5536ecb8f18a9d84d54d8591e5b27364443e121011600b69ab2
pdf-font-stream PDF embedded font (sfnt) at offset 0x10898 11368 bytes