Malicious PDF — malware analysis report

Static analysis result for SHA-256 e44b2ce0bac959ce…

MALICIOUS

PDF

93.0 KB Created: 2021-03-03 11:50:36 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9e088c304ed8cb5ad6a9206319bd4abb SHA-1: 98962b21fd76b7ff24e685cd88bb5e8bcbcb5296 SHA-256: e44b2ce0bac959ce2947e6744278977b4b8ff5d28a4ac60d1b3977777e823595
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains invisible links pointing to suspicious domains, designed to trick users into downloading further malicious content. The presence of embedded URLs and the nature of the heuristics suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=total+productive+management+meaning
    • http://italywom.space/true_football_2_patchn3aac.pdf
    • https://static.s123-cdn-static.com/uploads/4450733/normal_5ff4d0c6c7153.pdf
    • http://securityofusersdevicesonline.site/docker_deep_divei0yqs.pdf
    • https://static.s123-cdn-static.com/uploads/4420766/normal_5fe5c458f1ce3.pdf
    • http://aromaita.space/558177933092io1t.pdf
    • https://static.s123-cdn-static.com/uploads/4366057/normal_5fe39fc16db2a.pdf
    • http://akmurzina.com/wendys_french_fries_nutrition_information1dayb.pdf
    • https://cdn-cms.f-static.net/uploads/4369496/normal_5fdad32f7200d.pdf
    • https://cdn-cms.f-static.net/uploads/4421209/normal_60396ce17203b.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nafamaragisek/95352918193.pdf
    • https://s3.amazonaws.com/fadadedezeker/molomavakewe.pdf
    • https://s3.amazonaws.com/wanasuvedigo/35927820630.pdf
    • https://s3.amazonaws.com/rixevozajixezos/abrasive_wheel_test_questions_and_answers.pdf
    • https://s3.amazonaws.com/patotale/junji_ito_souichi_stories.pdf
    • https://s3.amazonaws.com/megodipewukitoj/25412160651.pdf
    • https://s3.amazonaws.com/jidagafinuxesu/56635483020.pdf
    • https://s3.amazonaws.com/jakujakula/linen_bed_sheets_canada.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001312a.bin
0bb7e07c6cc7cd1d605cceed1098f475371501298d9b4693baadf1fe39082e05
pdf-font-stream PDF embedded font (sfnt) at offset 0x1312A 5224 bytes
font_01_sfnt_off000142e2.bin
46666d6cbc4c5a8e38007c782013f33fe1f22df5751a159a3ac17b519b1957f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x142E2 10580 bytes