Malicious PDF — malware analysis report

Static analysis result for SHA-256 d28a6868e18b3b7d…

MALICIOUS

PDF

83.4 KB Created: 2021-02-26 23:52:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: aa90533e24fcbb83da88055ba24e5949 SHA-1: 17246432dfbde72cf1707e9af8526ad50373dadb SHA-256: d28a6868e18b3b7daa77f3fbd2072b9eeaf56f4500697c652cd2c56e55e9331f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains a malicious URL disguised as a SWOT analysis template. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URL points to a suspicious domain, likely intended to deliver a malicious payload or lead to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=swot+analysis+template+pdf PDF link annotation
    • http://lezigovedavide.getenjoyment.net/bbg_free_workout.pdfIn PDF document text
    • http://xojitufos.66ghz.com/unity_capture_screenshot_android.pdfIn PDF document text
    • http://rilomenininun.getenjoyment.net/tatumunakadefidixevo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jepinebawo/mera_bhai_tu_official_song_pagalworld.pdfIn PDF document text
    • http://papivis.epizy.com/bluestacks_app_player_x86_32_bit.pdfIn PDF document text
    • http://rafodize.rf.gd/binomial_model.pdfIn PDF document text
    • https://s3.amazonaws.com/nowonovege/cuneiform_avulsion_fracture_radiology.pdfIn PDF document text
    • https://s3.amazonaws.com/wufujudisu/delonghi_magnifica_xs_review.pdfIn PDF document text
    • http://lewefip.rf.gd/89098951648.pdfIn PDF document text
    • https://s3.amazonaws.com/batoragubukepo/camera_iphone_xs_max_apk.pdfIn PDF document text
    • http://zekarevuwo.epizy.com/zupetikopuwamite.pdfIn PDF document text
    • https://s3.amazonaws.com/tubukeganuji/love_in_the_time_of_cholera_setting.pdfIn PDF document text
    • http://bogurivesinoni.rf.gd/fedapum.pdfIn PDF document text
    • http://kesufelitam.rf.gd/cheat_minecraft_android_indonesia.pdfIn PDF document text
    • http://xopapodi.rf.gd/samegamubusolus.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010a25.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A25 5388 bytes
SHA-256: 5b59fcbc38027da22a59e37b36cfc5d18ca4a0ba6759caf40a6bea9c0f2ffc40
font_01_sfnt_off00011c88.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11C88 10596 bytes
SHA-256: 6348b913b5da80dc4e0be0b5fdbb3f27d9970baa305efec79dd2f89c664fe062