Malicious PDF — malware analysis report

Static analysis result for SHA-256 db7c0aba0ec279af…

MALICIOUS

PDF

84.7 KB Created: 2021-03-24 14:21:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 86a39446452cb3504dec4ea76ba3097a SHA-1: 406c2d2bd446b1248218d7afca0e5ed9af5d1cbd SHA-256: db7c0aba0ec279afe5b35945c371a4c8bee8d7176d82f104a3310e074d278054
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that directs users to a suspicious domain, likely for credential harvesting or further malware delivery. The document body, though heavily obfuscated, appears to contain search query-like text, suggesting a social engineering lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=what%2527s+good+to+mix+with+crown+royal+peach
    • http://levelupguild.com/how_to_make_a_paper_frog_origami_instructionsmg7di.pdf
    • https://static.s123-cdn-static.com/uploads/4373264/normal_5fc6d7d4c8342.pdf
    • http://cesaregaspari.com/nuradorirepijayrg22.pdf
    • http://moviesaddaa.online/86298759008cw7ik.pdf
    • https://cdn-cms.f-static.net/uploads/4379370/normal_602693493bb8e.pdf
    • https://cdn-cms.f-static.net/uploads/4443801/normal_601e64ee3852f.pdf
    • https://static.s123-cdn-static.com/uploads/4370540/normal_5fe2c70789ba3.pdf
    • http://logvoz.ru/retroarch_emulator_download_for_pc_32_bitinsif.pdf
    • https://static.s123-cdn-static.com/uploads/4405437/normal_5ffb1de8f001f.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cf075d60-af7c-4c71-a16c-5c8c125a9bb7.filesusr.com/ugd/cc03df_06111ae048934e27bfbe8b7b638d6407.pdf?index=true
    • https://s3.amazonaws.com/papuja/90431888779.pdf
    • https://s3.amazonaws.com/tumasun/raxufarefosivubuzal.pdf
    • http://jijaxipejor.rf.gd/35279470989.pdf
    • https://uploads.strikinglycdn.com/files/c88a145d-eba2-473a-879e-f649d14fe1fe/what_are_the_division_2_schools.pdf
    • https://s3.amazonaws.com/wazotojemov/46486378837.pdf
    • http://sosumanaxixit.epizy.com/interview_and_job_description.pdf
    • https://uploads.strikinglycdn.com/files/46f533b4-aee7-4b12-996d-e5b943f734ef/debuwimewisez.pdf
    • https://167c2301-eccc-4e3a-a609-38a4f17b9bf8.filesusr.com/ugd/b1dabf_3d2c63c460974eb0b2bb179c2f09ee80.pdf?index=true
    • https://s3.amazonaws.com/dovulavavo/abbyy_business_card_reader_2._0.pdf
    • https://700ceb37-22d2-47c5-9888-d858af679aee.filesusr.com/ugd/c345b0_de39e585bd4f4c36a42408ce13e27893.pdf?index=true
    • https://uploads.strikinglycdn.com/files/6de3528a-aa8c-477d-a5b1-8e134797d813/jenn_air_wall_oven_manual.pdf
    • https://uploads.strikinglycdn.com/files/c7f30697-f8d6-4d86-9ecc-27bce8fd3adb/ruvureserawisevowezor.pdf
    • http://kumugirenukelil.epizy.com/alzheimer_fisiopatologia_2020.pdf
    • https://uploads.strikinglycdn.com/files/88dacd37-41fe-4795-a1b9-922c29baec7a/bakeduwozekuvutirokazewem.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000109e0.bin
1371e1283eb7316abb5f3a703d33279bedfffd316d676e62b11258570e58921e
pdf-font-stream PDF embedded font (sfnt) at offset 0x109E0 5796 bytes
font_01_sfnt_off00011d9c.bin
86745e776ca216c1ada6f4e2d27994cf13760aa9538e8522c98bef8194672003
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D9C 10956 bytes