Malicious PDF — malware analysis report

Static analysis result for SHA-256 e164cd6582059add…

MALICIOUS

PDF

87.0 KB Created: 2021-03-16 08:04:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ca92a502eb798bcc07a7fc07cfbce9e5 SHA-1: 2e3e7aa790dd74b29cd1a22120020905c4dda6b2 SHA-256: e164cd6582059addb6b7d4a470080b17db6e596a6ed1dc39806fb335ee99e384
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a specific ClamAV detection name indicating it's a Pdf.Phishing.Trojan. The PDF contains an embedded URI pointing to a suspicious domain, which is a strong indicator of a phishing or malware distribution attempt. No scripts were extracted, but the presence of the malicious URL and the overall detection profile strongly suggest a phishing or trojan delivery vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9955

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/wix?keyword=arthur+q.+bryan
    • https://cdn.sqhk.co/madilaxetevo/fcJifPe/magical_forest_wallpaper_mural.pdf
    • https://cdn.sqhk.co/foxoxaze/Y6ibhhE/dukuliwunaxat.pdf
    • http://paselon.getenjoyment.net/wkhtmltopdf_page_break_inside_avoid.pdf
    • https://cdn.sqhk.co/jovakuki/ihJjfji/aws_iot_arduino_esp8266.pdf
    • http://mezajozugabaso.getenjoyment.net/potential_barrier_in_quantum_mechanics.pdf
    • https://cdn.sqhk.co/wisewuguv/7Bhf1wm/how_to_access_game_center_account_on_pc.pdf
    • http://nigavereke.mygamesonline.org/cannon_hotpoint_gas_cooker_manual.pdf
    • https://cdn.sqhk.co/werutojij/hepjaid/modal_verbs_examples_sentences.pdf
    • https://cdn.sqhk.co/kufiremikaf/chhggEj/brick_hospital_outpatient_lab.pdf
    • https://cdn.sqhk.co/menaleratupo/vieeoyZ/grand_truck_simulator_2_apk_data.pdf
    • http://mofemaruwek.sportsontheweb.net/2763398736.pdf
    • https://cdn.sqhk.co/foguwugafu/HLjaCjc/koppngen_sheet_music.pdf
    • http://xivekoto.medianewsonline.com/english_grammar_test_pre_intermediate.pdf
    • http://dusikazo.mypressonline.com/pathology_lab_report_format.pdf
    • https://cdn.sqhk.co/rudugebakivo/BCgjgns/deep_sea_mining_observer.pdf
    • https://cdn.sqhk.co/risubibasero/5xbdifu/musica_gratis_iphone_7.pdf
    • http://kepuxom.mypressonline.com/pradhan_mantri_awas_yojana_application_form_in_marathi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/ba2c026b-debe-42cc-8e40-9b98a62dfe47/vurazepekik.pdf
    • https://s3.amazonaws.com/pogolo/consul_template_vault_secret.pdf
    • https://uploads.strikinglycdn.com/files/8051bd6e-899c-4e26-a29c-8c04563a6574/zane_grey_free_kindle_books.pdf
    • http://wobanunep.myartsonline.com/how_is_faith_measured.pdf
    • https://uploads.strikinglycdn.com/files/f0370f59-a083-4fa9-9a25-02552230b58b/porque_no_se_puede_eliminar_una_conversacion_de_instagram.pdf
    • https://s3.amazonaws.com/bipepezuwed/17432235107.pdf
    • https://s3.amazonaws.com/tazibabebamep/galaxy_call_recorder_app.pdf
    • https://uploads.strikinglycdn.com/files/1c3d39c5-ea5c-4465-8e2d-b81057746dba/1960s_dc_comics_for_sale.pdf
    • https://s3.amazonaws.com/foneniz/libertango_sheet_music_sax_quartet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010942.bin
80a103d756970accc8c13f70f6d945c33147b3a7b222ad4c12d27fd380d60f24
pdf-font-stream PDF embedded font (sfnt) at offset 0x10942 4556 bytes
font_01_sfnt_off000118b0.bin
826e8f45b13387f34509dc8473c7d0cebf5b78f30ecb3c89110620aef8130427
pdf-font-stream PDF embedded font (sfnt) at offset 0x118B0 11428 bytes
font_02_sfnt_off00013f11.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x13F11 4324 bytes