Malicious PDF — malware analysis report

Static analysis result for SHA-256 dae51d3f40aaf8e9…

MALICIOUS

PDF

78.1 KB Created: 2021-03-31 19:13:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3e50b0ca4f9550af52103e881dd05472 SHA-1: 25d16da19d386b651827e2b397466f3fca7a376e SHA-256: dae51d3f40aaf8e9bf061828d0c2614a18aa6a4dcfe2571910f56aacc81fdfb6
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with high-severity heuristics indicating suspicious links to external domains. The presence of multiple embedded URLs, including one disguised as a PDF on a suspicious domain, strongly suggests a phishing or malware distribution attempt. The document body, though heavily obfuscated, contains metadata related to wkhtmltopdf, indicating it might be a generated document used to mask malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9961

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/wix?keyword=minion+hair+salon+game
    • http://pukatasenibi.iblogger.org/movie_sequels_coming_out_in_2021.pdf
    • http://uaregroup.com/vudejorojejejef9cw1l.pdf
    • https://cdn.sqhk.co/musutalivun/cxPPP2Y/bubble_shooter_2020.pdf
    • http://mavito.online/app_store_free_for_macw2ibp.pdf
    • http://capridigi.com/abyssinica_amharic_keyboard_for_macp95ib.pdf
    • https://cdn.sqhk.co/xawodoze/uuijibm/snapple_k_cups_discontinued.pdf
    • http://loginwithfb.site/90015212062v0gdv.pdf
    • https://cdn.sqhk.co/noviraxat/jSvGic2/international_financial_reporting_standards_ifrs_9.pdf
    • http://doporujela.iblogger.org/80530419785.pdf
    • https://dexazime.weebly.com/uploads/1/3/1/4/131437554/2763555.pdf
    • https://bemebedutor.weebly.com/uploads/1/3/4/6/134624352/zopunajila.pdf
    • http://uspeh.icu/97577703891u86b.pdf
    • https://cdn.sqhk.co/dufikibagi/zSihG44/45230657302.pdf
    • http://on-arenas.com/gmat_formula_sheetatq0q.pdf
    • http://jijexuvekenim.iblogger.org/sikinevowa.pdf
    • https://tebiwexarug.weebly.com/uploads/1/3/1/3/131380746/6321720.pdf
    • https://xibokesobapud.weebly.com/uploads/1/3/0/7/130776239/wegolubujoxu.pdf
    • http://card2card-perevod24.site/xajigfwtrz.pdf
    • http://world-wildshop.com/rogiregoxiwobildgr1.pdf
    • http://brightshopbg.xyz/ischgl_snow_report_forecast58x4s.pdf
    • http://aov.one/calligraphy_handwriting_practice1aigz.pdf
    • https://cdn.sqhk.co/jeporikate/hBuhiE9/48530133127.pdf
    • http://justamorem.com/354111222922kef0.pdf
    • http://front-glass.website/how_to_make_shadow_puppets_handshedlp.pdf
    • http://lnstagramverifiedbadgeshelpcenters.net/play_free_texas_holdem_replay_pokerj1nf6.pdf
    • http://zoneeuro.pro/darekidaselokivumam7fgaz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://temekem.epizy.com/69932953658.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f536.bin
ca7877bba8320645314359def1892824e1c29d480cfd1a2a64c4d1def8238cd2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF536 5104 bytes
font_01_sfnt_off0001066e.bin
8016467fe57fc89d8b54f092704c028a2db37adfbb01f2e8b152574fec5f595a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1066E 10772 bytes