Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1600af9da757fcf…

MALICIOUS

PDF

78.8 KB Created: 2021-03-18 15:28:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8edd7d162d59f633001dae76145df722 SHA-1: d5e169afba29793426926136e683de5ea0b1996b SHA-256: f1600af9da757fcf9d0460842a13b38ccf173af7f27c49555807bde311649814
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an embedded URL that points to a suspicious domain, identified by heuristics as a potential phishing or malware distribution vector. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=que+es+abrogar+y+derogar+pdf
    • https://cdn-cms.f-static.net/uploads/4453334/normal_6037dce93972b.pdf
    • https://cdn-cms.f-static.net/uploads/4392647/normal_5fd658618f8b1.pdf
    • https://cdn-cms.f-static.net/uploads/4449014/normal_603f01d0b85db.pdf
    • https://cdn-cms.f-static.net/uploads/4486963/normal_600ad75a29990.pdf
    • https://zixijatujomalul.weebly.com/uploads/1/3/5/9/135962278/4201086.pdf
    • https://nesojikav.weebly.com/uploads/1/3/1/3/131398336/3735117.pdf
    • https://demuxovepeb.weebly.com/uploads/1/3/4/3/134311881/9847941.pdf
    • http://liberum.sportsontheweb.net/77359923668.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://lulanikigog.epizy.com/fopolutoxibejino.pdf
    • http://jonokib.rf.gd/how_to_record_interim_dividend_paid.pdf
    • https://s3.amazonaws.com/limewub/how_does_a_walgreens_humidifier_work.pdf
    • http://lapetagalelan.myartsonline.com/alucinaciones_por_drogas.pdf
    • http://wisalawisavu.epizy.com/behringer_x32_manual_english.pdf
    • https://s3.amazonaws.com/lebaxa/pip_for_python_3._6_windows_10.pdf
    • https://s3.amazonaws.com/zesixefe/57008916109.pdf
    • https://s3.amazonaws.com/gurupixabogivaz/jenagudipezotudagir.pdf
    • http://puwagof.rf.gd/letter_d_worksheets_free_printables.pdf
    • http://digegaleviverab.rf.gd/marketing_download_free.pdf
    • http://tusewareja.epizy.com/3934269958.pdf
    • http://verepuremi.rf.gd/dragonfable_stats_guide_for_rogue.pdf
    • https://s3.amazonaws.com/wupiwupiwot/science_a_closer_look_grade_4_workbook.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f17b.bin
18c5e908c2b2e48fcfa95c1f1614f913185d9554a152ed01e044527740bf4d71
pdf-font-stream PDF embedded font (sfnt) at offset 0xF17B 5480 bytes
font_01_sfnt_off0001042b.bin
697c7944644da5b4538958c054ba7eb068b2bf991c7d01b3bddb8cb76757f1cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x1042B 12408 bytes