Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2cba99edd9e71d8…

MALICIOUS

PDF

85.0 KB Created: 2021-03-22 14:25:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3696e77b4e53100fb07a91436044910a SHA-1: 77875f0783ee61c9f24b851592e514b3d3d78aa9 SHA-256: d2cba99edd9e71d8cc15400d7018483cedca51a5fa72a98b7972fec8b5d21120
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URL that masquerades as a 'paladin classic pvp guide', likely a lure to trick users into downloading further malicious content. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest an attempt to redirect users to potentially harmful external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/wix?keyword=paladin+classic+pvp+guide
    • http://tixokapine.mypressonline.com/what_commands_can_you_ask_alexa.pdf
    • https://cdn.sqhk.co/simubekoz/6hfpaGV/bongo_mix_video.pdf
    • https://cdn.sqhk.co/dugelabomaw/ihYey4k/tik_tok_video_editor_app_download_apk.pdf
    • https://cdn.sqhk.co/tumosirewuw/39heehj/60448950428.pdf
    • https://cdn.sqhk.co/xelajura/ifihdgd/86994667289.pdf
    • https://cdn.sqhk.co/buvaboda/jbQjhKm/best_apple_watch_6_screen_protector.pdf
    • http://wewogokuwidu.mywebcommunity.org/sefugojevixegazuxofiwexo.pdf
    • http://tupujetu.sportsontheweb.net/caries_dentinaria.pdf
    • https://cdn.sqhk.co/vefusujix/gh6hfij/homeschool_planner_2020_printable.pdf
    • https://cdn.sqhk.co/vakolitakap/dtyjajj/cotton_classing_hvi.pdf
    • https://cdn.sqhk.co/joremeve/jjihdgg/blockchain_technology_simple_definition.pdf
    • https://cdn.sqhk.co/fugapaloter/ejaK9ij/spades_plus_game_rules.pdf
    • http://rijexofugovu.medianewsonline.com/kewotodu.pdf
    • https://cdn.sqhk.co/zovaratigu/0MqhjKH/commercial_water_slides_for_sale_near_me.pdf
    • http://piriveva.scienceontheweb.net/winnie_the_pooh_complete_30_books_gift_box_collection.pdf
    • https://cdn.sqhk.co/xelalizogim/b3icBXs/limidix.pdf
    • https://cdn.sqhk.co/supetudoti/pXayaA4/ruramiduxubed.pdf
    • http://bidizujimon.getenjoyment.net/is_waterpik_water_flosser_good.pdf
    • http://zipubezexupoka.mywebcommunity.org/bavubefaro.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://vujijemu.atwebpages.com/5286198808.pdf
    • https://uploads.strikinglycdn.com/files/27871e73-3c9a-42f3-9aca-ef8f549dfb26/2003_saturn_vue_parts_for_sale.pdf
    • https://uploads.strikinglycdn.com/files/087ccc37-9a5f-4c88-8249-5e88546c75f5/fijozun.pdf
    • https://uploads.strikinglycdn.com/files/f82fc90a-89d8-41b4-ad61-c235c42a3534/what_are_the_most_common_french_words.pdf
    • http://zonatitusajobo.onlinewebshop.net/isometric_drawing_questions.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010f57.bin
f6c716426a10235b2bc0d9ed8ff7a57ee1311e79f3280bd3163472c0f9f23444
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F57 5208 bytes
font_01_sfnt_off00012129.bin
5907e303bffddc36f63145a6466268291606ca7bab9f16e4d818d3a562f7ac39
pdf-font-stream PDF embedded font (sfnt) at offset 0x12129 10960 bytes