Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9a4e4a0807ea2c7…

MALICIOUS

PDF

164.8 KB Created: 2021-04-05 13:37:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6766a082f2fa44a791231b89881482cd SHA-1: 752119fb12e4f5c8ad18cb50f1b57778f633102d SHA-256: e9a4e4a0807ea2c7e772bc492f15f69bba869a3ab11c68cc662e24adc2e1c228
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URL disguised as a book title, likely intended to trick the user into downloading a malicious payload. ClamAV and ML classifiers strongly indicate maliciousness, and the presence of external URIs points to a phishing or credential harvesting attempt. No scripts were extracted, but the PDF structure itself is suspicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/award?keyword=behavioral+science+in+medicine+2nd+edition+pdf
    • https://cdn.sqhk.co/vimexuda/jhbPjbe/koxuzifawamipabujo.pdf
    • http://pegejoruvufiron.sportsontheweb.net/tabla_periodica_con_grupos_y_periodos.pdf
    • https://cdn.sqhk.co/pisomuma/QdqhaOM/xoxefavirapewusofabixedew.pdf
    • http://kewokuxumuzig.medianewsonline.com/jojamikejatozamepurimata.pdf
    • http://vurovolapoza.mygamesonline.org/3898997683.pdf
    • https://cdn.sqhk.co/nilesatu/kjiEazp/flick_kick_football_legends_best_players.pdf
    • https://cdn.sqhk.co/folamudoj/gijderC/ronibakuguwi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/1cb8ded4-2f95-4e12-bcfa-9f3277f9a1c0/82196662306.pdf
    • http://levapoloj.onlinewebshop.net/40055437384.pdf
    • https://uploads.strikinglycdn.com/files/96e236bc-386b-443a-b962-aa669151022a/what_are_the_sizes_of_clipper_guards.pdf
    • https://uploads.strikinglycdn.com/files/2db8e3ee-5e46-4da2-ac28-d67f175a66e1/5028003713.pdf
    • http://vasakuzepilaxi.onlinewebshop.net/81647389292.pdf
    • https://uploads.strikinglycdn.com/files/ddb52022-b884-4894-92cf-645a6a8dbf09/foundation_trilogy_review.pdf
    • https://uploads.strikinglycdn.com/files/af52476c-a2a4-4a66-b936-258271150537/resumen_libro_de_genesis_en_la_biblia.pdf
    • https://uploads.strikinglycdn.com/files/43a5612b-b8b2-4f1f-aa5c-b726da1858c9/31220178272.pdf
    • https://uploads.strikinglycdn.com/files/c2e54708-6078-4131-9c6b-ecd5e62abfa7/how_to_clean_backbeat_fit_headphones.pdf
    • https://uploads.strikinglycdn.com/files/8509dfe3-4b98-41d8-ac56-79292d74ce79/64039699826.pdf
    • https://uploads.strikinglycdn.com/files/35b9ca1a-05f9-4961-b41d-ae1c5dca9fb9/why_wont_my_fitbit_inspire_charge.pdf
    • https://uploads.strikinglycdn.com/files/3501cec8-603a-46bc-b364-bba6316817d9/81489681098.pdf
    • https://uploads.strikinglycdn.com/files/dae3bdc1-12d8-47a3-bd85-bb1a340b0108/tigaka.pdf
    • https://uploads.strikinglycdn.com/files/aea0a451-0db4-4e4e-811a-2cdf31b8f19d/87575715012.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000245bd.bin
3425ff7d34a6c91750088dd45e654032ea4ed2270eb6f4518bb5bcae8330531b
pdf-font-stream PDF embedded font (sfnt) at offset 0x245BD 5636 bytes
font_01_sfnt_off000258cb.bin
bbd4212ac004f0dfb25da39cbed066c0dcad489540bc05a80ea8edfd2401a25a
pdf-font-stream PDF embedded font (sfnt) at offset 0x258CB 12444 bytes