Malicious PDF — malware analysis report

Static analysis result for SHA-256 e231ddb9e9244d07…

MALICIOUS

PDF

75.4 KB Created: 2021-03-11 23:29:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8df747f990ee1dd66c8f7e5041fd10fa SHA-1: 96963b72ac4c222e736177b41f92fcca82f99d86 SHA-256: e231ddb9e9244d07cdfc24f5827040cd401927f1e802a4ae6931a24814a4d6b9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that redirects to a suspicious domain, likely as part of a phishing or social engineering attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. The document body, though heavily obfuscated, appears to contain metadata related to search queries, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=great+depression+yahoo+answers
    • https://cdn.sqhk.co/zupuguvawaj/TGEhahh/war_of_independence_1857_causes_in_urdu.pdf
    • https://cdn.sqhk.co/daxegajok/hc2Ngc1/alien_escape_pod_scene.pdf
    • http://towonededuv.medianewsonline.com/tennessee_cottage_food_laws.pdf
    • http://ridunculus.com/runescape_corrupted_creatures_slayer_guidexfbu0.pdf
    • http://wusator.mygamesonline.org/consecuencias_politicas_de_la_caida_del_muro_de_berlin.pdf
    • http://luziniwanemek.sportsontheweb.net/beginner_violin_pieces.pdf
    • https://cdn.sqhk.co/xugumewaz/igi6hgo/awm_gun_sound_message_tone_download_mp3.pdf
    • http://luxshop21.site/how_long_is_harry_potter_6_without_creditsn48cp.pdf
    • http://center-about.com/acer_aspire_e15_display_price_in_sri_lanka6wl5r.pdf
    • http://xakidofe.sportsontheweb.net/kawasaki_fh580v_oil_filter_cross_reference.pdf
    • http://dorulezebum.sportsontheweb.net/16317731724.pdf
    • https://cdn.sqhk.co/pidodalatip/fYpg7NP/12013044265.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/acecf631-41a0-47e1-8a8e-ea81d29a1662/bissell_big_green_clean_machine_1672_parts.pdf
    • https://uploads.strikinglycdn.com/files/c1c2cff2-3044-4b85-8a75-c771239ebb2e/53259776382.pdf
    • https://s3.amazonaws.com/viromibukoleliw/muzomogefarunisogatu.pdf
    • https://s3.amazonaws.com/firigugixujotov/english_idioms_translated_to_french.pdf
    • https://uploads.strikinglycdn.com/files/a15057a6-fdba-438b-8c8c-963fba1e305d/behringer_xenyx_x2222usb_22-channel_mixer_with_usb.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea98.bin
ed2256d9cd5da390700e13c8040c9250255048d3680fe38e9534363c573e1feb
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA98 5240 bytes
font_01_sfnt_off0000fc78.bin
03eb23ad723a7f372dd8205da4ef2b459999edd46182f9f125ac6b525280ddf1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC78 10672 bytes