Malicious PDF — malware analysis report

Static analysis result for SHA-256 d5d93036cfea06ea…

MALICIOUS

PDF

183.1 KB Created: 2020-12-30 05:20:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: 5394177c45fed61c4b305e94b4faa821 SHA-1: dc1b5e8968b88bca6f3ae4ae99d3ba94a1a1e4dd SHA-256: d5d93036cfea06ea3081ae21466b236aafc189ef364532cb45f40fc26a9faa6f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, consistent with a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7532

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/strik?utm_term=chess+piece+moves PDF link annotation
    • https://ziresaro.weebly.com/uploads/1/3/4/5/134509830/13459ca.pdfIn PDF document text
    • https://fofafobef.weebly.com/uploads/1/3/4/3/134349457/koxegulebugexe.pdfIn PDF document text
    • https://vosilidasum.weebly.com/uploads/1/3/2/7/132740263/8445940.pdfIn PDF document text
    • https://kevapesezivobi.weebly.com/uploads/1/3/4/8/134893959/guzabokap.pdfIn PDF document text
    • https://doxujivadew.weebly.com/uploads/1/3/4/8/134875716/tasinebojagexaremo.pdfIn PDF document text
    • https://putoluxadap.weebly.com/uploads/1/3/4/7/134734973/gugirevulojijo.pdfIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.fontrix.comhttp://www.nhncorp.comIn PDF document text
    • https://s3.amazonaws.com/tomaxade/bud_light_pool_table_light_with_pool_balls.pdfIn PDF document text
    • https://s3.amazonaws.com/lolaritemukole/parix.pdfIn PDF document text
    • https://s3.amazonaws.com/ruzaganog/kejoxudod.pdfIn PDF document text
    • https://s3.amazonaws.com/zazelujeju/protocolo_sonda_vesical.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4afcde9e-0376-4e4a-9b7b-5a0c95450fbf/12710680146.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off0001d9d7.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1D9D7 5040 bytes
SHA-256: ae87c6c485b06803319b6a2aa6f3b8774410abca21c18e83d167d7ff03bf4e5c
stream_014_off000268d6.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x268D6 32100 bytes
SHA-256: 58647143d3db1dd5a47ec5d8f684fd2d7691655938003eb6a73480ba3f1d1913
font_00_sfnt_off00014d2f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14D2F 6444 bytes
SHA-256: 23bed797d97bda55248fc61ba84ad3b4940ee20791600990b0cfcb37dc87a329
font_01_sfnt_off00015cf4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15CF4 10996 bytes
SHA-256: bdb3907f80dc12ab1323bf2a3de5c394648af55f3d7ee12f7098ebf3d88b3337
font_02_sfnt_off00018198.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18198 4800 bytes
SHA-256: 2ab43873e2d9b5cc98efa687fdbe91cc1ade7d10434033fd55e90ccc651660c9
font_03_sfnt_off000191c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x191C9 7860 bytes
SHA-256: f7123753348414a8ab839ca7d0f1387b0a935019cff8d0c6629ed3396e97917f
font_04_sfnt_off0001a92b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1A92B 7344 bytes
SHA-256: e5084c37e03851de7268fcc97eb2ac62691866fda7db587ad09f9b1323b058ea
font_05_sfnt_off0001c15a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C15A 6812 bytes
SHA-256: 60b7124ada80f5b7a0349c7cf3ae0b6ed530aa79b393c9dbe46804f0930ba6b4
font_07_sfnt_off0001ea68.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1EA68 6192 bytes
SHA-256: 5f4af773527940789d02be637e8ed294ddece1d8e01dbddf896c9c45618604f5
font_08_sfnt_off0001fefc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FEFC 6536 bytes
SHA-256: 008f3a650337b50cc77745f493bd4ab80cacd57c9d34b57c7bf2838d0778949e
font_09_sfnt_off00021018.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21018 1684 bytes
SHA-256: 88476e476f8010b318a3ce9868032c1e42aeda216ab62a39a7bdf58b32e7a4df
font_10_sfnt_off0002187b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2187B 31960 bytes
SHA-256: 753f0fddb113fa3fae48d394fddb90631e48c6813aca061cb8aa495b5934bf8a
font_12_sfnt_off0002ab75.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2AB75 2092 bytes
SHA-256: 8f996de1fb0694511c2ae052f7d11f51114b3848761256a980882e876cdc9c9b
font_13_sfnt_off0002b499.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B499 6292 bytes
SHA-256: 0c2df04ecfd8149a332282e55bd2607699a94deded1028b24f7bbe72c5bd5808