Malicious PDF — malware analysis report

Static analysis result for SHA-256 f42dbe9b15c2b3db…

MALICIOUS

PDF

54.2 KB Created: 2020-11-17 02:43:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aafae5678ec4e3b094b6221aaad7311a SHA-1: 04b163bfabf81fc4ffca5d58804ea6f6b13dcde3 SHA-256: f42dbe9b15c2b3db7287054c432e26289c14644b31ff380d9979a28d6791d278
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to scientific information to mask the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7929

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?utm_term=carnot%2527s+second+law+of+thermodynamics
    • https://cdn-cms.f-static.net/uploads/4365652/normal_5f9af5e6a1542.pdf
    • https://cdn-cms.f-static.net/uploads/4380086/normal_5f8d42a250f9a.pdf
    • https://cdn-cms.f-static.net/uploads/4382420/normal_5f8ba6297f1f5.pdf
    • https://cdn-cms.f-static.net/uploads/4389127/normal_5f92442cee5c6.pdf
    • https://cdn-cms.f-static.net/uploads/4384310/normal_5f904a06ba5f7.pdf
    • https://cdn-cms.f-static.net/uploads/4379485/normal_5fae850b23e61.pdf
    • https://cdn-cms.f-static.net/uploads/4489237/normal_5faa5dcd3cdaf.pdf
    • https://cdn-cms.f-static.net/uploads/4366623/normal_5f87e0ad8706c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/07974d44-380e-4cf1-9ffb-2f63b8937626/8058361467.pdf
    • https://s3.amazonaws.com/welutizenop/46227315581.pdf
    • https://uploads.strikinglycdn.com/files/f7efb489-92b5-40b0-976b-fd57868e3021/jaterufugitozojib.pdf
    • https://s3.amazonaws.com/widuxade/gear_s3_asking_for_pin.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c2b6.bin
b3a1af7550e3706bbbf62d58e8bba72b753ea4923fbd695826cca6b2dbcc1bbb
pdf-font-stream PDF embedded font (sfnt) at offset 0xC2B6 5392 bytes