Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4702f392a6a7318…

MALICIOUS

PDF

80.2 KB Created: 2021-01-07 22:53:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e7c3735018a8c9f6ddde71333d2fc3b4 SHA-1: 43243e1bb9d0d81d0837293d057c89a8b033130f SHA-256: d4702f392a6a73183798f759071f297f7d1807ae8005ed33d1168045f65b35db
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic suggest it's designed to exploit users by directing them to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/123?utm_term=rogue+rls-1+lap+steel+guitar+uk
    • https://cdn.sqhk.co/fisejadiruw/p1Ggie8/lulegu.pdf
    • https://cdn.sqhk.co/fakosopalo/Cggjb7w/best_voice_chat_pc_games.pdf
    • https://cdn.sqhk.co/fejavegiwo/0yicNjj/mozom.pdf
    • https://cdn.sqhk.co/noruwotil/jgeDmge/tiktok_filter_camera_app.pdf
    • https://cdn.sqhk.co/vikoparif/Wjfgigg/87195273807.pdf
    • https://cdn.sqhk.co/kifavubivelo/wShcggq/crossword_mysteries_episode_3_bianca.pdf
    • https://cdn.sqhk.co/dupeguwova/idTidty/67933868719.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/8e3d26c9-6648-4180-9229-d8d1d9c4a049/zudonujosetujev.pdf
    • https://uploads.strikinglycdn.com/files/8a0f6c62-28b9-4a47-9156-d0012c632613/11th_standard_english_guide.pdf
    • https://uploads.strikinglycdn.com/files/1bce5522-c895-495b-91d4-fe0e7f4994d8/foruvimesulumodow.pdf
    • https://s3.amazonaws.com/bezorito/bollywood_horror_movies_old.pdf
    • https://uploads.strikinglycdn.com/files/04f0ab8c-e505-4a49-9aa4-89bfee487148/7611273973.pdf
    • https://uploads.strikinglycdn.com/files/7e4ff2cd-f6fb-4650-bf18-4744ae5bfe80/80480249326.pdf
    • https://s3.amazonaws.com/pasawe/aspen_hysys_7._3_crack.pdf
    • https://s3.amazonaws.com/fewunadupop/love_on_the_brain_saxophone_sheet_music.pdf
    • https://uploads.strikinglycdn.com/files/1ea5e4a3-e9ec-419d-9f85-85bade6b455c/cdc_abstract_control_model_acm_samsu.pdf
    • https://uploads.strikinglycdn.com/files/7826ad92-e8a9-4fb8-b123-d070af54d969/gajubiz.pdf
    • https://s3.amazonaws.com/tibanepoxilibud/the_crucible_movie_questions_answer_key.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0f2.bin
0bf0c54488c68e98e1327194bb7e7940f433c6ea110aed08b982de8a214b248b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0F2 4916 bytes
font_01_sfnt_off000101df.bin
de53c49d9a3d6385491880fb9662378b89842ad7e382a833fc3a4349309cd866
pdf-font-stream PDF embedded font (sfnt) at offset 0x101DF 10560 bytes
font_02_sfnt_off000125d2.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x125D2 4324 bytes