Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1cc3bcfa8e5e5c1…

MALICIOUS

PDF

76.8 KB Created: 2021-02-08 18:36:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-31
MD5: 9387d3a1edc5a5ffb77f37274f21a073 SHA-1: b50708c56cce2ba9ef84ee9e614f97a5692a9bb6 SHA-256: f1cc3bcfa8e5e5c1bb9d7fdd733d4d00d5ccc78bb95890baff244391792a091a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating it is malicious and has been flagged by a machine learning classifier and ClamAV as a phishing trojan. It embeds a URL that, when accessed, likely leads to a malicious payload or phishing page. The document body, though partially corrupted, suggests a lure related to 'worksheet answers'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/aws?utm_term=types+of+intermolecular+forces+worksheet+answers PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4457272/normal_6003b59e9accd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366366/normal_601223d119752.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4495240/normal_5ff27f323804e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4458631/normal_5fe90ddd69e33.pdfIn PDF document text
    • http://bogplaktnc.fun/fluid_power_with_applications_7th_edition9nz7u.pdfIn PDF document text
    • http://kersita.fun/class_notes_templatecunst.pdfIn PDF document text
    • http://vermono.site/temple_run_3djwnbp.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4491687/normal_5fe19a9fb953d.pdfIn PDF document text
    • http://logvoz.ru/44737185796ew3y.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384154/normal_6018e09174e28.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://pedojup.rf.gd/girusijewigigasuradilutu.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec8f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC8F 5464 bytes
SHA-256: 6ae4dd679170b4362391ea7d97a43c230b5f52fa0ec4a06da78d9083980ccb98
font_01_sfnt_off0000ff17.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF17 11492 bytes
SHA-256: b3648ba22fe0da9d276e697e9490dc11e41adae2303b5aa47ddb21792b7e6c3d