Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0c18d3ddb683290…

MALICIOUS

PDF

81.4 KB Created: 2021-03-29 04:12:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b8533728a73978ae447020ddbf488f57 SHA-1: ba9b721d0bd67c43d4111c468f4069f4363ecdda SHA-256: e0c18d3ddb683290dc66df1c1055d3f12766570f337ae2498a98ca19164113a3
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a lure related to a 'promise of employment letter malta' and includes an external URI pointing to a suspicious domain. ClamAV detection and ML classification strongly indicate malicious intent, likely for phishing or malware delivery. No scripts were extracted, but the presence of an external URI suggests a potential download or redirection to a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=promise+of+employment+letter+malta
    • https://cdn.sqhk.co/xipapotug/ioidgfZ/69214140201.pdf
    • https://cdn.sqhk.co/mogilirexexa/gpIStIT/jw_library_for_pc.pdf
    • https://cdn.sqhk.co/befozaxulot/l3gfogc/dikopidelixi.pdf
    • https://cdn.sqhk.co/boxokozofe/ejguZhc/blade_craft_mod_apk_unlimited_money.pdf
    • https://cdn.sqhk.co/nafusomo/dujdkia/wuwogaji.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/73efe918-0780-4aac-aa0f-459386f281ee/suunto_ambit_3_peak_sapphire_hr_test.pdf
    • https://s3.amazonaws.com/roxawo/vuvalavoximot.pdf
    • https://uploads.strikinglycdn.com/files/51097810-f52b-46fd-b80d-71f4882dd26f/how_many_calories_in_arbys_potato_cakes.pdf
    • https://uploads.strikinglycdn.com/files/04d734ec-52a9-48d5-b7ef-ceaf332dece4/what_does_vanya_do_in_the_umbrella_academy.pdf
    • https://uploads.strikinglycdn.com/files/a689a41f-f486-4cd4-aab3-c433c1cba6fa/thetford_toilet_faults.pdf
    • https://uploads.strikinglycdn.com/files/17ea03cb-5ddf-4d2a-9425-bb8948c80b5a/artistic_anatomy_book.pdf
    • https://uploads.strikinglycdn.com/files/4246a920-8d5f-4fdd-b7f4-bcf7a7aef4dc/polaris_3900_parts.pdf
    • https://uploads.strikinglycdn.com/files/19a86f7d-61b2-474b-b857-a1fc4a029f59/nigedazixux.pdf
    • https://s3.amazonaws.com/pekatikisuruki/xigaramitidutuli.pdf
    • https://s3.amazonaws.com/gumegulaxi/your_grace_is_enough_chris_tomlin_lyrics.pdf
    • https://uploads.strikinglycdn.com/files/d71a2d3b-f323-4a41-81eb-d3783adffb29/savukoxi.pdf
    • https://uploads.strikinglycdn.com/files/f87f5b8e-4b51-42fc-9730-59f2698ba1bc/gallows_of_madness_review.pdf
    • https://s3.amazonaws.com/zurovajij/symantec_vip_self_service_portal_christiana_care.pdf
    • https://s3.amazonaws.com/mivokozibu/puzugoduxixajozupa.pdf
    • https://uploads.strikinglycdn.com/files/93e17196-e95c-4704-be65-2ea334f9161c/74935262138.pdf
    • https://s3.amazonaws.com/tidigudetefumof/zombie_catchers_apk_mod_unlimited_money.pdf
    • https://uploads.strikinglycdn.com/files/5e79935b-c92b-43c1-a454-4152d71525d7/daxutinepek.pdf
    • https://s3.amazonaws.com/libowebujakux/69717759873.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010164.bin
f0aa29cbeb471600797c1a9f61b22ed7ec27d2d5b733944d8f531da4a0f11c50
pdf-font-stream PDF embedded font (sfnt) at offset 0x10164 5152 bytes
font_01_sfnt_off000112dc.bin
8cb6de32e6f09207949600e4875ac77124a7f8e8343ae391544e1c88b5a8e125
pdf-font-stream PDF embedded font (sfnt) at offset 0x112DC 10904 bytes