Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8e13f4e89a211b1…

MALICIOUS

PDF

93.4 KB Created: 2021-02-12 12:02:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c4a69bea5e03b54c4d676ccae73cc6e9 SHA-1: 961dbbcb617a4392b92ed94aacfb617de73bd246 SHA-256: d8e13f4e89a211b1f8e4c9c1e01f76cd04288ebc1c73696d9002248dacd6ed2c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains embedded URLs pointing to potentially malicious domains. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware delivery. Although no scripts were explicitly extracted, the presence of multiple suspicious URLs suggests the document is designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=vua+choi+bai+yugioh+tap+1
    • https://zewogamiwivu.weebly.com/uploads/1/3/4/3/134313422/janudilesen.pdf
    • http://zoomita.space/21227261778zpha2.pdf
    • http://realnoe-obshenie.online/xizidu497sd.pdf
    • http://igclienteam.com/gezizuxezafikswnn.pdf
    • http://remontvorot24.com/55568187724l0y8n.pdf
    • http://beststudent.space/7_minute_vocal_warm_up_pro_modk81un.pdf
    • http://ubsvp.com/briton_ferry_fc_formw5ziz.pdf
    • http://ostanni.fun/gugukomasomuyel53.pdf
    • https://fubomagasikeka.weebly.com/uploads/1/3/4/4/134474343/494708.pdf
    • http://youralteragoods.com/controlled_potential_coulometrykymxv.pdf
    • http://trenketo.buzz/peer_editing_checklist_middle_schoolo8vm5.pdf
    • http://polnews.xyz/406372004142eh37.pdf
    • http://romeital.space/bach_cello_suite_56ph52.pdf
    • https://piworanup.weebly.com/uploads/1/3/2/6/132681558/b34218fcab3f2.pdf
    • http://ketosimple.online/shankar_bhagwan_ke_gana8aksp.pdf
    • http://2gusevshop.space/blacklight_retribution_game_free_for_pcemz43.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fotepopunaj/adobe_photoshop_elements_problems.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012926.bin
78b945702169caeec96b9de88b3a4984dfa00e52a8f3e774502dd8ec714bad25
pdf-font-stream PDF embedded font (sfnt) at offset 0x12926 5148 bytes
font_01_sfnt_off00013abf.bin
57dbacfb073c8bf83dba66eab014127251a5591dc0855e2ce6f61eed57cea390
pdf-font-stream PDF embedded font (sfnt) at offset 0x13ABF 14588 bytes