Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee9807686871fd2d…

MALICIOUS

PDF

69.6 KB Created: 2021-03-25 17:53:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 28bc1702875ea8b7e85b398be7d18b9c SHA-1: 9ee6013499edd4450cf95c3336165d238afe9ce1 SHA-256: ee9807686871fd2d3b149e380520fa6d29f27d45ab7300f7e5d83099b4fc313f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, and ClamAV detected it as a phishing trojan. The ML classifier also strongly indicated maliciousness. While no scripts were explicitly extracted, the presence of external URIs and the overall detection suggest the document is designed to redirect users to a malicious site, likely for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=free+3+point+shootout+basketball+games
    • https://liwuvena.weebly.com/uploads/1/3/1/3/131398027/22602cf.pdf
    • https://junerokiwoji.weebly.com/uploads/1/3/0/7/130775834/4271739.pdf
    • http://zexezolevonim.iblogger.org/97529385981.pdf
    • http://austritkfa.com/123_magic_freekuzh2.pdf
    • http://limaxinsto.xyz/kuwizuluwejesesavoxuwolugq4x8.pdf
    • http://cafe-cok.ru/pbs_nova_parallel_worlds_parallel_lives0hd2n.pdf
    • http://manibupefif.mypressonline.com/reading_and_writing_shs.pdf
    • https://fuwewarudizikip.weebly.com/uploads/1/3/4/6/134644733/mufonodujewog-femiv.pdf
    • https://mugibamarenov.weebly.com/uploads/1/3/4/1/134109107/jonivipobokos_vemivo_nosovajepula_gojeti.pdf
    • http://arm-watch3.club/kamanunijo3llqt.pdf
    • http://help-bluebadgecustomer.com/bulleit_bourbon_whiskey_ryevv7un.pdf
    • http://lemafesopeposuz.mywebcommunity.org/arches_and_lintels_carpentry_joints.pdf
    • http://waxedeb.getenjoyment.net/aliran_psikologi_behaviorisme.pdf
    • http://wapividazofar.scienceontheweb.net/foxuboxivujafudipose.pdf
    • http://zuraribofib.22web.org/strong_vs_weak_acids_worksheet_answers.pdf
    • http://jekeluxuto.mywebcommunity.org/how_to_explain_the_sun_and_moon_to_a_child.pdf
    • http://naturwows.space/employment_grievance_letter_templatekqax0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://sogoxutagejuno.atwebpages.com/angulo_de_treitz.pdf
    • http://gubadif.myartsonline.com/59347172824.pdf
    • http://nawokuzowurib.epizy.com/wing_chun.pdf
    • http://fuvamawijivef.atwebpages.com/asperges_me.pdf
    • http://xinotitatidab.rf.gd/que_es_filosofia_del_derecho_definicion.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d07a.bin
d7d586113606b7b81e484f3be7dcc104c08accece78c7a04d85af2fd3b0ca3ff
pdf-font-stream PDF embedded font (sfnt) at offset 0xD07A 5556 bytes
font_01_sfnt_off0000e335.bin
c63be8fe3f29964c81c4f60e534ca8ff3ba155b18a9529c394e15c30a3518987
pdf-font-stream PDF embedded font (sfnt) at offset 0xE335 10932 bytes