Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0cc0a7f054cd16f…

MALICIOUS

PDF

69.7 KB Created: 2021-01-13 20:19:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: b70dda76849cb0eb05ad2b217111b8f4 SHA-1: 381fde3c1ec7d87495e2f4200783320aabbe8480 SHA-256: d0cc0a7f054cd16f7d1c2f854c6c5232ea7882029ef88afdf341e0a1c3b0f02b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that, when visited, likely leads to a phishing or malware distribution site. The document body, though heavily obfuscated, references 'Aplia answers macroeconomics chapter 11', suggesting a lure to entice users to click the malicious link. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?utm_term=aplia+answers+macroeconomics+chapter+11 PDF link annotation
    • https://site-1176192.mozfiles.com/files/1176192/family_mountain_bike_trails_near_me.pdfIn PDF document text
    • https://site-1180086.mozfiles.com/files/1180086/maps_to_the_stars_movie_480p.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4499636/normal_5feff651a6128.pdfIn PDF document text
    • https://site-1177347.mozfiles.com/files/1177347/vugelagiluvuxiselul.pdfIn PDF document text
    • https://cdn.sqhk.co/pibilebomek/ggHjggf/wazuwitovor.pdfIn PDF document text
    • https://site-1177404.mozfiles.com/files/1177404/player_potentials_pes_2020.pdfIn PDF document text
    • https://cdn.sqhk.co/litalile/EjcbKWd/95696033008.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/vutame/florida_odometer_statement_form.pdfIn PDF document text
    • https://s3.amazonaws.com/dibedamoka/bnha_heroes_rising_full_movie_online_dub.pdfIn PDF document text
    • https://s3.amazonaws.com/dejazuvorira/kejudimupatogimidaz.pdfIn PDF document text
    • https://s3.amazonaws.com/tozaduliwubega/munorubidofesi.pdfIn PDF document text
    • https://s3.amazonaws.com/gezetega/9555635150.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d2fa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD2FA 5308 bytes
SHA-256: b84094e355ed13ea191e913d14a0c43b5618c67a9c44afe0cc3af40de2285cd7
font_01_sfnt_off0000e4f3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE4F3 10720 bytes
SHA-256: 8446d81c5548db6794e03ef7f063ec2b1b93028bae95c011923eda7509727c64