Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0354300f753227c…

MALICIOUS

PDF

89.7 KB Created: 2021-03-02 21:58:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a61dc2896d95d7ceb1cd289e564ddfe6 SHA-1: 2e80196162995f832d7056ef9f9b15cc0470e019 SHA-256: e0354300f753227cf634a40663266387248e7a8458bfd014887bc614ce04cd06
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that mimics a search result for a game, likely intended to trick the user into clicking it. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of embedded URLs and the PDF structure suggest it's designed to redirect users to malicious content, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/wix?keyword=road+of+the+dead+2+unblocked+games
    • https://cdn.sqhk.co/nilulugaj/jahgiev/reludetewesuku.pdf
    • https://cdn.sqhk.co/zubavagi/11FCwid/jufojuluxivadifop.pdf
    • http://kaxiwemusemoj.mypressonline.com/badedo.pdf
    • https://cdn.sqhk.co/ferorigife/K3hghif/tank_hero_laser_wars_apk.pdf
    • http://wetitafege.iblogger.org/are_snap_on_tools_lifetime_warranty.pdf
    • http://sawedes.mywebcommunity.org/short_plot_summary_of_the_maze_runner_book.pdf
    • http://wivuperafuzo.mypressonline.com/tackle_football_playbook_maker.pdf
    • http://xepidenad.scienceontheweb.net/strike_industries_ar-15_lower_receiver_pin_kit.pdf
    • https://cdn.sqhk.co/kolokejo/dSzEqjc/choppa_fortnite_map.pdf
    • https://cdn.sqhk.co/jafipago/bybkgiY/lopogoduteko.pdf
    • http://xiwesesakuvel.medianewsonline.com/pipenipitonawi.pdf
    • https://cdn.sqhk.co/bilanogakiw/gisd3hi/100_doors_games_2020_escape_from_school_answers.pdf
    • http://wigogaduxatinuv.iblogger.org/cement_cube_test_report.pdf
    • http://nuwefug.22web.org/81503934083.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://merapuw.epizy.com/promissory_note_modification_agreement_form.pdf
    • http://gawexerexi.rf.gd/64636511638.pdf
    • http://mulizin.epizy.com/bexuzefu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fcaa.bin
9a4bacc71cdcc1557b0beaeb8aa7e71977498ebc704c4c8b901238750ff9acd9
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCAA 5516 bytes
font_01_sfnt_off00010f46.bin
b9fc5d4222b98a74808c2cb190b556f62484929013b23466e6276c7069b6ef88
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F46 10300 bytes
font_02_sfnt_off000132a0.bin
bc564e5e589069a720b6ea32bd83521dc36f039e7b0dc2f86cf08793940a3fba
pdf-font-stream PDF embedded font (sfnt) at offset 0x132A0 16868 bytes
font_03_sfnt_off00014aa6.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x14AA6 4324 bytes