Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1a0b324d2b04f54…

MALICIOUS

PDF

94.3 KB Created: 2021-03-18 00:20:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a4b35b7e101ff6120634c8b28dcb6a2f SHA-1: 9070bd6461c8e9025f811edd98a60e64885f728a SHA-256: d1a0b324d2b04f54961d198913c96047b854d544b634a6742e14b237f965d813
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was identified as malicious by ML classifiers and ClamAV, with a critical heuristic firing for ClamAV detection. It contains an embedded URI pointing to a suspicious domain, likely for phishing purposes. The document body is heavily obfuscated and unreadable, suggesting it is not intended for direct user interaction but rather to facilitate the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=extreme+heli+boarding+addicting+games
    • http://airet.space/how_to_clean_bosch_washing_machine_tubtjdt6.pdf
    • http://salearea.pro/acid_rain_solutionskwp81.pdf
    • https://rujibuteza.weebly.com/uploads/1/3/5/3/135308743/416691ce.pdf
    • http://checkmycredit.info/bosukewamatopiveweporokb8gvh.pdf
    • https://nufusuninad.weebly.com/uploads/1/3/4/6/134609023/47452ebc.pdf
    • http://5-euro.info/nafuzunefidt7wt.pdf
    • https://cdn.sqhk.co/velabolo/ijf1gh3/tulolixoxononula.pdf
    • https://cdn.sqhk.co/mojekuvugise/biccDig/jibomelezipovevazaret.pdf
    • https://cdn.sqhk.co/tibidimewako/gghiiha/mobopelaxagibiligefexip.pdf
    • https://jagozuru.weebly.com/uploads/1/3/4/3/134360529/4543187.pdf
    • http://dotenipago.medianewsonline.com/que_es_eficiencia_en_administracion_del_tiempo.pdf
    • http://pifafixejizigu.scienceontheweb.net/24692491041.pdf
    • http://presentinsta.online/shadowkeep_release_date30xl7.pdf
    • https://kazowotamije.weebly.com/uploads/1/3/4/0/134012594/maperawipu-nuzuderalirako.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gufopexolax.myartsonline.com/rts_24_bus_schedule.pdf
    • https://s3.amazonaws.com/xafaxotaful/nujil.pdf
    • https://s3.amazonaws.com/tedowafomaru/acs_national_cancer_information_center.pdf
    • https://s3.amazonaws.com/lopadivupudexa/dnd_5e_wild_magic_sorcerer_guide.pdf
    • https://s3.amazonaws.com/zetubakuz/frozen_cartoon_full_movie_mp4.pdf
    • https://uploads.strikinglycdn.com/files/5f4046ac-860d-47c0-baf2-1683a03de69d/kitchenaid_superba_dishwasher_troubleshooting.pdf
    • https://uploads.strikinglycdn.com/files/f10c469e-3ef1-4e6e-afa6-f0e61be8d07d/tp_link_wpa4220_installation.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001341f.bin
0940863a05d5721a06e9ad1e905aa51b0c2447064a6466123d4933eaaf1d8d0f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1341F 5516 bytes
font_01_sfnt_off000146b8.bin
545a590f9686ad80e2d983f118bd0da036e15b8e248b29be2852fcb0657c3fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x146B8 10828 bytes