Malicious PDF — malware analysis report

Static analysis result for SHA-256 e81b3776d0785633…

MALICIOUS

PDF

84.3 KB Created: 2021-03-22 11:17:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 013525cdf0fb2c4697b0cf5aa5be7a7a SHA-1: 3124f26f97042cfc07af119bb8081c60e42aae0e SHA-256: e81b3776d07856330b78c10aae9ee404de58a8b8ba9244cf10508c0397a384b6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains an external URI pointing to a suspicious domain, likely intended to host a malicious payload or redirect the user to a phishing site. The document body, though heavily obfuscated, appears to be a lure related to project management techniques, aiming to trick the user into clicking the embedded link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=critical+path+analysis+and+other+project+network+techniques+pdf
    • http://phrensy.co/45195392063dcrjx.pdf
    • http://nickned.me/matematicas_financieras_anualidades73guk.pdf
    • http://goodnaturak.space/50524225862o0bv9.pdf
    • http://com-servers.online/16_channel_mixer_price_in_nigeria16ui2.pdf
    • http://dostafood.xyz/19171129300h8e2j.pdf
    • http://goodsun.space/o_que__o_que__piadas_infantilj3s27.pdf
    • http://pirewixuzejetin.iblogger.org/vowubaxaloviv.pdf
    • http://siwosupegejolop.medianewsonline.com/fomolo.pdf
    • http://specialsale.info/turtle_beach_stealth_500_xbox_one_setupmk464.pdf
    • http://nomudepalak.medianewsonline.com/tazilowaledejotejevo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://baverasoge.epizy.com/84907691011.pdf
    • https://s3.amazonaws.com/jidosatikim/gaussian_quantum_chemistry_software.pdf
    • http://tizoraponu.rf.gd/microsoft_word_label_template_21_per_sheet.pdf
    • http://tutalogivenerok.epizy.com/scantron_answer_sheet.pdf
    • https://s3.amazonaws.com/zafaronivaj/zosemufoturibiwujaxo.pdf
    • https://s3.amazonaws.com/kawotexulozax/entrapment_infidelity_book_4_read_online_free.pdf
    • http://pusapovewazigu.onlinewebshop.net/10547747704.pdf
    • http://daripesobad.epizy.com/emerson_lc320em2_wall_mount_screw_size.pdf
    • http://dodemupisam.epizy.com/carbon_democracy_book.pdf
    • https://s3.amazonaws.com/lovomijelun/how_to_write_binary_covalent_compounds.pdf
    • http://wekumut.epizy.com/what_can_i_make_ahead_for_thanksgiving_dinner.pdf
    • https://s3.amazonaws.com/busutafitufe/78477702708.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010a3f.bin
57c622a1713c5d88cd38074c789a82ee7c862eac697f671b5438e4837965d71e
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A3F 5608 bytes
font_01_sfnt_off00011d62.bin
a49d6454fd91c3a98ec9142f36fe11241f6b6c13d45b2e1cc4cb147a8c192e17
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D62 11104 bytes