Malicious PDF — malware analysis report

Static analysis result for SHA-256 e815f0fd061163bb…

MALICIOUS

PDF

70.0 KB Created: 2021-05-11 09:04:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: d594a94e49dc89b23531764665f51b69 SHA-1: 229e6135e156785cc8d2c0fc71ac6635f6e5367a SHA-256: e815f0fd061163bbeb40bac2a16882d75cd09cad775c931f0b83e653cc7332ca
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. The embedded URL points to a domain that is likely part of a phishing campaign, disguised as a free printable. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/strik?utm_term=free+printable+taboo+cards+pdf PDF link annotation
    • http://konolux.medianewsonline.com/pdf_to_word_converter_software_download_full_version_free.pdfIn PDF document text
    • http://fuwikodafe.iblogger.org/adding_and_subtracting_fractions_worksheets_and_answers.pdfIn PDF document text
    • http://vofigasu.medianewsonline.com/86709244704.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://vitusaw.rf.gd/amazon_echo_dot_2nd_generation_user_manual.pdfIn PDF document text
    • http://jonesojawu.myartsonline.com/wikoluworajujara.pdfIn PDF document text
    • https://a04ad255-06d6-4b17-97e7-91173d300295.filesusr.com/ugd/6864df_1da350f9d24f4835855aa12e93076b5c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/412d1a21-0be7-4c7f-8300-400916bfab79/war_horse_harley-davidson_phone_number.pdfIn PDF document text
    • https://s3.amazonaws.com/pevuwarobuvowa/nourishing_traditions_book_of_baby_and_child_care.pdfIn PDF document text
    • http://gadoxijumulop.epizy.com/10095546916.pdfIn PDF document text
    • https://s3.amazonaws.com/jejulurowev/27357135877.pdfIn PDF document text
    • https://9c33b4df-6f14-41ad-9e94-a3a23f7ed20d.filesusr.com/ugd/2a975f_924ccb99e8e04a5d91dac5873ab3e584.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/fukezavazuj/bodie_kane_and_marcus_2014_investments_10th_edition_mcgraw_hill.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f92d3d0a-660e-4f58-8d6f-d69c698fcbf6/zexusegufej.pdfIn PDF document text
    • https://s3.amazonaws.com/fosagoba/kogipez.pdfIn PDF document text
    • http://vogapodidojuguf.myartsonline.com/airliner_classics_magazine.pdfIn PDF document text
    • https://aa6d2f86-95e2-42cc-897e-6bbd71c3a116.filesusr.com/ugd/78daac_c78f88acc7f84a828b3c200197107419.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/gizonukorad/fufejo.pdfIn PDF document text
    • https://5ec50ee2-6c76-415b-b731-82d7de26534b.filesusr.com/ugd/826e74_36d702713d5a4c318cc2eb04024daec9.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/18761856-de5b-4620-97e1-32bb9757df62/what_is_ieee_format_for_reference.pdfIn PDF document text
    • https://s3.amazonaws.com/tugabijenovili/bal_krishna_hd_movie.pdfIn PDF document text
    • https://s3.amazonaws.com/jajoxulabojaso/xuliragiweforoviwaz.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d666.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD666 5244 bytes
SHA-256: 20a904d001f8cd1aa77b382e6996bc8b1fa7765904d88ca76970d1b43256832a
font_01_sfnt_off0000e841.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE841 10160 bytes
SHA-256: f8e56687b7c94f4c3cac364acf0419327fc692970b95ebf72c8e65d2a96c9c12