Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfa04529d8b712fa…

MALICIOUS

PDF

78.0 KB Created: 2021-03-25 03:26:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 79fed37a0e459ca2978a48e7e04ba00d SHA-1: 6c207bf0771a866239548568b7c67d6598814f67 SHA-256: dfa04529d8b712fa05bb1abca854238bd54ae7f9a15c5c7c56d1183584adb091
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that directs users to a phishing page disguised as a government bill. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were extracted, the presence of an external URI and the document's deceptive content suggest it is designed to trick users into visiting a malicious website.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=bernie+sanders+medicare+for+all+bill+pdf
    • https://cdn-cms.f-static.net/uploads/4408873/normal_5fd2a8c2b8273.pdf
    • https://cdn-cms.f-static.net/uploads/4483833/normal_603f21554cfe4.pdf
    • http://blockingscenery.com/graco_pack_n_play_manual_2010mxmbw.pdf
    • http://pubomoxagu.22web.org/ramkanai_das_baul_bengali_songs_free.pdf
    • http://classkaod.ru/rexuruxutapefalidududotud0k9t.pdf
    • https://static.s123-cdn-static.com/uploads/4452862/normal_5fec69bfbb6ec.pdf
    • https://cdn-cms.f-static.net/uploads/4415308/normal_6011fb8b594b7.pdf
    • https://cdn-cms.f-static.net/uploads/4500911/normal_604513a3ddf8f.pdf
    • http://copalofa.site/71246832500eziem.pdf
    • https://cdn-cms.f-static.net/uploads/4476011/normal_605971e6d6b17.pdf
    • https://cdn-cms.f-static.net/uploads/4446784/normal_6012725eb9f78.pdf
    • http://leafester.online/huawei_p30_pro_software_updatecamyt.pdf
    • https://cdn-cms.f-static.net/uploads/4494436/normal_6039f4de42db7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/8ba5c3f6-62c4-4931-9f9b-abfd353e540d/vugoburadovorabop.pdf
    • https://uploads.strikinglycdn.com/files/af8c1671-0453-4715-abfa-861640496909/ap_calc_ab_2017_multiple_choice_answers.pdf
    • https://s3.amazonaws.com/poguvelefa/54466006629.pdf
    • https://s3.amazonaws.com/xajowu/vewenezajalasefusuja.pdf
    • https://s3.amazonaws.com/gapivegek/ifixit_pro_tech_toolkit_guide.pdf
    • https://uploads.strikinglycdn.com/files/175bbf9a-25b1-46ad-bbc7-d39e2429b963/8466256125.pdf
    • http://fufinekudag.epizy.com/35024845618.pdf
    • http://butejoki.rf.gd/75567213758.pdf
    • http://wazododasexixak.rf.gd/bhu_bsc_bio_entrance_exam_syllabus_2020.pdf
    • https://uploads.strikinglycdn.com/files/70059ac3-317a-4f0c-a028-47ce48919c1a/denon_avr-1513_specifications.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f013.bin
469f74c1b3189198c00389887bbb7553d2a834d20c724119cf918e231dcb27d9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF013 5492 bytes
font_01_sfnt_off000102a9.bin
2b9875ecabf93223eb0cd50fe030a21e142a63b75ee7b3ef538a000a1dcd950e
pdf-font-stream PDF embedded font (sfnt) at offset 0x102A9 11600 bytes