Malicious PDF — malware analysis report

Static analysis result for SHA-256 e610710fa49d2054…

MALICIOUS

PDF

93.7 KB Created: 2021-03-06 14:05:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1f4654b5283ac44b3816f903b6974f6b SHA-1: 247c7199e339043b138720adb9bda0f9037dd0c4 SHA-256: e610710fa49d20544ce9eb0725e95c7b6df3a8e3c60bbf1d47052e0f109fe2d3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a URL that mimics a search result for educational information, likely to trick users into clicking it. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to malicious sites, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=loudoun+county+public+schools+student+calendar+2020
    • http://capridigi.com/valipogda7o4.pdf
    • http://cardio-active.site/edelweiss_guitar_chordsv9idx.pdf
    • https://cdn-cms.f-static.net/uploads/4449615/normal_5fda829488c0e.pdf
    • http://simultaneously.space/anti_adblock_killer_chrome_androidw3wh4.pdf
    • http://select-get.top/are_bosch_washer_dryers_any_goodnda7p.pdf
    • http://cloudplay.xyz/golf_buddy_vs4_price2fgu2.pdf
    • http://ompala.store/56405349013lrx0c.pdf
    • http://itslm.fun/rewuvoszkt.pdf
    • http://forsage.pw/ohio_high_school_libero_tracking_sheetrj6ju.pdf
    • http://eurozone.pro/siwexadifoxolemoxap95fx2.pdf
    • http://pycnidwzxc.info/robejegeet3rq.pdf
    • http://dragonflysagewellness.com/50729036002heqd8.pdf
    • https://static.s123-cdn-static.com/uploads/4375358/normal_5ff559f9d6954.pdf
    • http://paypallsecurity.com/sample_of_partnership_deedmsxpe.pdf
    • https://cdn-cms.f-static.net/uploads/4466413/normal_601a38a4a3d60.pdf
    • http://shoop-fo.ru/31471507491r9g66.pdf
    • http://eferevole.com/gilafufef371yn.pdf
    • http://blancop.xyz/how_do_you_troubleshoot_a_boilervr2uo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/fefurorobumi/what_is_measure_in_music_tagalog.pdf
    • https://s3.amazonaws.com/numunenoji/17917406393.pdf
    • https://s3.amazonaws.com/vitelitubovuluj/kididewi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001257c.bin
24263c99808fd5b88d4cd032627b5e0bb05e2aede3a60a5f240ab54603a9d57d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1257C 5500 bytes
font_01_sfnt_off0001381a.bin
666fdabec5b1ac88891a19c1ad155795588f5af6959f1696e2c29cfa594d34c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1381A 10240 bytes
font_02_sfnt_off00015b22.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x15B22 4324 bytes