Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea76cd6d39cc5469…

MALICIOUS

PDF

528.2 KB Created: 2021-03-04 21:28:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-07
MD5: bc073d3118ffced5cc569b7e895b9f9f SHA-1: 85de9705bcd8472ae2bf7705355c5e066f62eb09 SHA-256: ea76cd6d39cc54690cc6b073b9e7d79c3e9e9bd06bd8e62a071c586d15469728
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is a strong indicator of a phishing or malware distribution attempt. The ML classifier and ClamAV detection further support its malicious nature. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, likely for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7050

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/strik?utm_term=how+to+remove+motor+from+delta+unisaw PDF link annotation
    • http://xekumaluvox.iblogger.org/dd_3.5_how_many_feats_per_level.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4500208/normal_603d49adbb716.pdfIn PDF document text
    • http://xxlmature.site/naga_patrilineal_societyga01n.pdfIn PDF document text
    • http://ketosimple.online/2928127233df57r.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4479224/normal_5fd6c4ea2fa61.pdfIn PDF document text
    • http://segway-wheelchair.ru/jokunowesutrzv39.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4530910/normal_600dcc44bbba8.pdfIn PDF document text
    • http://zavarivaemvmeste.ru/51805317024o831w.pdfIn PDF document text
    • https://cdn.sqhk.co/gederanew/iuSqQbi/virus_deaths_history.pdfIn PDF document text
    • http://nalowisep.22web.org/bigbasket_app_free.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4415754/normal_60036d88a967e.pdfIn PDF document text
    • https://cdn.sqhk.co/rabovafom/ibQhbTc/sukeserifezosulapojorife.pdfIn PDF document text
    • http://fontawesome.iohttp://fontawesome.io/license/In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
    • https://uploads.strikinglycdn.com/files/b20b8568-e984-464e-ae32-7719afe712e0/what_is_a_healthrider.pdfIn PDF document text
    • http://waxewib.epizy.com/what_size_tire_does_a_2015_toyota_corolla_take.pdfIn PDF document text
    • http://waduxixefe.rf.gd/totakobuwajegiva.pdfIn PDF document text
    • http://gazisemodab.epizy.com/capacitores_resumo.pdfIn PDF document text
    • http://japotegalavig.epizy.com/how_to_use_pilates_stretch_bands_for_abs.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8b869461-840e-4b3c-a8d7-0e0b0b0b9f8b/77323791257.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlTibetanIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0007577e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7577E 8192 bytes
SHA-256: dedfa55e4b5318b9309ed5386e90324e97bba2e8ef580daee552e70dcb21017d
font_01_sfnt_off00076d15.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x76D15 22832 bytes
SHA-256: ba7affe25aed0ed84e38fd79fea19dffa7307464a9780b2968fb3d59c0953068
font_02_sfnt_off0007a7f6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7A7F6 2912 bytes
SHA-256: f725b616a1add9e943c6eb4fb6e7c9f4993d2e6aee03ef0522a7e9ab2836f318
font_03_sfnt_off0007b251.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7B251 5164 bytes
SHA-256: df77f62e5d470510fb846c2a6207b5adc8aa4e93a32d272fa2d93f289189524b
font_04_sfnt_off0007c3e1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7C3E1 8976 bytes
SHA-256: e6ef1070fe110e09fdf6bef938d0dd901ba4047105bbf626610727e05d38d2aa
font_05_sfnt_off0007d59d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7D59D 2472 bytes
SHA-256: ada4b7b48bf158e34fdae87598298d145645e924b0f9803cd978cdb4c780c1fb
font_06_sfnt_off0007dfdd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7DFDD 18312 bytes
SHA-256: 4d4ecb03cca25e1476c26cd3165f67459e9b9c88b3e2cdc7b84b5d515fc385a8
font_07_sfnt_off00081998.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x81998 16372 bytes
SHA-256: 6626c22b3734253b5b0a5e1e87eee91d698076d44366fcf462ec5070b49608c9