Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcdbb5ba99e188cd…

MALICIOUS

PDF

68.9 KB Created: 2020-12-19 03:42:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: 54fcd2e5768120f33fdca3e7a296949f SHA-1: 6170735fcff4d0c2ffdc49596187105dc2c91d24 SHA-256: dcdbb5ba99e188cd6658ae882c62a6d9de00c87606f02b9970adb11e128df997
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URL that leads to a suspicious domain, likely part of a phishing or scam campaign. The document body, though partially corrupted, suggests a pretext related to toll-free calls to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffnew.ru/wb?keyword=should%20you%20answer%20a%20toll%20free%20call PDF link annotation
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/nupotukig/pesquisa_bibliogrfica_livro.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e2944d43-a869-4033-a953-4d7531dd7895/77344059749.pdfIn PDF document text
    • https://s3.amazonaws.com/taguxif/karaoke_night_flyer_template.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf54abf81c9a2a0c98f6b5/1606374571886/the_origins_and_history_of_consciousness.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc7b8c4418d7934ac78d68d/t/5fcffbc5f5eb572b8a2a54a9/1607465928033/piano_keys_octaves_numbered.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc32cce11f6a4198494824d/t/5fcc760e978da30c56f63d54/1607235087992/flight_simulator_games_for_pc_free_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/97c1007b-5627-4e96-908b-97dd3ad9c710/58808184923.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc5d8daa5bc066edfc77a21/t/5fd74bd2ab77727176ab9977/1607945171520/pulmonary_embolism_guidelines_acc_aha.pdfIn PDF document text
    • https://s3.amazonaws.com/zafirawit/abripedic_crisp_percale_sheets.pdfIn PDF document text
    • https://s3.amazonaws.com/webipejonavuv/o_que__sociologia_editora_brasiliense.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc57f453398ff75154cec93/t/5fc5e909e18c5c478ec79651/1606805770945/coin_master_hack_without_verification.pdfIn PDF document text
    • https://s3.amazonaws.com/didowugorokirug/bufinawojubexonegik.pdfIn PDF document text
    • https://s3.amazonaws.com/fatisake/2010_toyota_camry_hybrid_owners_manual.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d25f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD25F 5408 bytes
SHA-256: c7d6a362fc6644b2286c81c4f87ebae4da166d0a40ab7aabf2379c1652a9be8a
font_01_sfnt_off0000e4d3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE4D3 10064 bytes
SHA-256: b4f2844028faee8e60c2f74ca186abde64bed739bc62dd75fc1b7f2ab966d41c