Malicious PDF — malware analysis report

Static analysis result for SHA-256 daebe804d83bdd04…

MALICIOUS

PDF

79.4 KB Created: 2021-03-29 10:32:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: a024a6bb8db599673cb178b0cb5f9e84 SHA-1: 41578c36b56d97a7d4168bce69566b7ce6ab614c SHA-256: daebe804d83bdd0408ec705161a2b9be717292a1593a720b8a8f369415f52f8b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URL that redirects to a suspicious domain, likely serving as a lure for phishing or malware distribution. The document body, though heavily obfuscated, appears to be related to search terms, further supporting the phishing lure hypothesis.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/award?keyword=arm+cortex+a76+pdf PDF link annotation
    • https://cdn.sqhk.co/nefikelifu/ibibhcE/1868037272.pdfIn PDF document text
    • https://cdn.sqhk.co/dukosisevu/h7LVo7V/abc_of_electrical_engineering_free.pdfIn PDF document text
    • https://cdn.sqhk.co/fudamozomeb/jjfry82/demon_s_souls_dragon_god_punch.pdfIn PDF document text
    • https://cdn.sqhk.co/guzufaseba/aJvijQH/46594023406.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/bffa801f-13df-4dae-98d7-ce0e592b9615/que_diferencia_hay_entre_calculo_integral_y_diferencial.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/76cfdd21-6dc7-4cb6-90f1-e0dfb1a11497/how_to_make_hampton_bay_fan_go_in_reverse.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c66f522a-072d-4d53-9102-f39aeb123b57/zuruwakaxumoxijemade.pdfIn PDF document text
    • https://s3.amazonaws.com/wuvepilamamuse/3.5_exterior_angle_theorem_and_triangle_sum_theorem_worksheet_answer_key.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d76aa3ee-e05c-4911-988e-b0062d732600/verifone_commander_certification_training.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b8cbac80-9d68-4b80-bdee-f2acbdfadd09/free_advanced_christmas_piano_sheet_music.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b8be0ebf-7074-480a-907c-5f008886c387/pilurij.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6c5789fc-bd15-4a3e-b8d1-7d87d1c149aa/how_to_tell_if_furnace_filter_needs_replacing.pdfIn PDF document text
    • https://s3.amazonaws.com/vizegemawokaxe/kupulozakikumononowox.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/77f872d9-69c7-48bc-948c-cba5bf67d704/use_d-link_dir-655_as_access_point.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/27c7267b-24d9-4f31-9cf3-01a2293bf1f7/chakra_books_nz.pdfIn PDF document text
    • https://s3.amazonaws.com/jebupofedijakuk/40413167693.pdfIn PDF document text
    • https://s3.amazonaws.com/nawosineromigi/bejubim.pdfIn PDF document text
    • https://s3.amazonaws.com/tazibabebamep/caresource_prior_authorization_form_for_ohio.pdfIn PDF document text
    • https://s3.amazonaws.com/wifiduxezo/how_accurate_is_the_relion_blood_pressure_monitor.pdfIn PDF document text
    • https://s3.amazonaws.com/kavifunaruvi/573117950.pdfIn PDF document text
    • https://s3.amazonaws.com/lonozote/solid_converter_v9.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b4834aa-05bb-4f57-b234-15b5472675f1/ribejewobulobawiku.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7de.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF7DE 5384 bytes
SHA-256: 432ff688aaeffda0e583d338baf95acc006b252bc137fa4c5bd02b4c3945caab
font_01_sfnt_off00010a27.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A27 11296 bytes
SHA-256: a94ce24a29118274122448af7ae9008412e071bf8dc347c16b76184dcd4f083f