Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc25bc8a34b6bca7…

MALICIOUS

PDF

210.1 KB Created: 2021-03-19 05:54:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-28
MD5: 674f0e1fde150b5d7fa4b1be2c1dbcf5 SHA-1: 63eac72bce8d42f170d64584d993eb23668b070b SHA-256: dc25bc8a34b6bca74066b32712377d2a5c6f7cfd9ed3187e2a2c8858e0d23449
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, identified by ClamAV as a phishing/trojan. The ML classifier also flagged it as malicious. While no scripts were explicitly extracted, the presence of external links and the overall detection suggest an attempt to redirect the user to a malicious site, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9896

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=matlab+%25E8%25A7%25A3%25E6%2596%25B9%25E7%25A8%258B+root PDF link annotation
    • http://dapujabowigu.sportsontheweb.net/53269660161.pdfIn PDF document text
    • http://fujavexawagul.iblogger.org/past_simple_irregular_verbs.pdfIn PDF document text
    • https://denogowozule.weebly.com/uploads/1/3/5/3/135326247/59c26530a2.pdfIn PDF document text
    • http://raxanoxev.22web.org/nolowotowepiru.pdfIn PDF document text
    • https://loloxemevo.weebly.com/uploads/1/3/0/7/130739498/1588338.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zesixefe/the_devil_wears_prada_clothing.pdfIn PDF document text
    • http://dunedobaxapekir.epizy.com/popumajafa.pdfIn PDF document text
    • https://s3.amazonaws.com/nerugiraxura/30673398424.pdfIn PDF document text
    • http://dumadanovoj.rf.gd/jonijewivigiboredalotig.pdfIn PDF document text
    • https://s3.amazonaws.com/fapaga/4938993449.pdfIn PDF document text
    • http://bavotuvezomevi.myartsonline.com/plenty_of_room_at_the_bottom.pdfIn PDF document text
    • http://bopadem.rf.gd/vatejalu.pdfIn PDF document text
    • https://0dd0cd87-80d3-4eb5-b9c6-73c43c3a6fca.filesusr.com/ugd/f0b6b3_7a310b2f62114b20a863c5c0426ce6c9.pdf?index=trueIn PDF document text
    • http://vawerudarasikow.myartsonline.com/weber_charcoal_grill_starter_kit.pdfIn PDF document text
    • https://s3.amazonaws.com/bodajaku/nevagamed.pdfIn PDF document text
    • http://zixadadafupeg.epizy.com/baseball_card_game_for_android.pdfIn PDF document text
    • https://s3.amazonaws.com/votubukaxogilix/56784181167.pdfIn PDF document text
    • http://setuxar.rf.gd/physics_notes_for_neet.pdfIn PDF document text
    • https://dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com/ugd/c8df25_1f1dbcc325854b56bec59021ce2fb367.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011866.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11866 155012 bytes
SHA-256: 8a3cdb6cbb008c3d0b5aaa248f7efd64d80904d78bcd11467f0aaf8f5b948f48
font_01_sfnt_off0002de45.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2DE45 3820 bytes
SHA-256: fb794342ea050f8580c04fa1c0babc47363334ca416a5506b9717769e3fcce12
font_02_sfnt_off0002ebaa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2EBAA 4648 bytes
SHA-256: 2064e474356ea650fd99ac818fb7c84a4fa491914a70b9924e7f8ac98a827048
font_03_sfnt_off0002fb8d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2FB8D 11544 bytes
SHA-256: f786d21b0e94bda175d7e2b86870ff06c21a0f0ae028f9a77d78e1e8a59f1566
font_04_sfnt_off0003232f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3232F 16124 bytes
SHA-256: ea6052ef55e08e89ccc5a799dfce8a06378356e1da8c225497d2bb8357cb94e1