Malicious PDF — malware analysis report

Static analysis result for SHA-256 f44907c522f22774…

MALICIOUS

PDF

71.6 KB Created: 2020-12-02 09:16:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 730fb34ac1148ad5a7affe92a32169eb SHA-1: 77c8c92ab4e0d1dbb1a6528b760d3e8ea250e50a SHA-256: f44907c522f22774e8a01289520f6141826b353da1416db7d19df1ca44f7ef06
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is a strong indicator of a phishing or malware distribution attempt. The ML classifier and ClamAV detection further support its malicious nature. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to redirect the user to a malicious site, likely for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=anarchy+advantages+and+disadvantages+quizlet
    • https://static.s123-cdn-static.com/uploads/4404503/normal_5fc71a6080727.pdf
    • https://cdn-cms.f-static.net/uploads/4406229/normal_5f9dd80be9253.pdf
    • https://cdn-cms.f-static.net/uploads/4413590/normal_5f9443c3e185e.pdf
    • https://cdn-cms.f-static.net/uploads/4449422/normal_5fa2982247662.pdf
    • https://cdn-cms.f-static.net/uploads/4488560/normal_5fb84ac3568e0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/c4731e7b-3f5f-4b9a-91dd-41a996638815/zakupanilaxanoperaz.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4c5b08845d092480a218/1606372448222/wow_orc_last_names.pdf
    • https://uploads.strikinglycdn.com/files/5378a48a-01ae-468c-85a3-f97be5d7ab30/chapter_17_the_west_exploiting_an_empire.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4e929d79364840848fdf/1606373011729/71613907484.pdf
    • https://uploads.strikinglycdn.com/files/59d22fca-02a0-40f9-b72c-debf0e2e9013/autocad_2014_torrent.pdf
    • https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf5109bc819f1cf4cf2cb5/1606373644268/20625747943.pdf
    • https://uploads.strikinglycdn.com/files/a7d39776-2989-4cb3-9d33-806073681308/dezexafudoweturipogedov.pdf
    • https://static1.squarespace.com/static/5fc5355c24b06a7eb31bb18b/t/5fc6588d9b1ed03538b63a73/1606834318032/wulafobagi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cd0e.bin
58160ebec04fa0cad822d3e0eaeddd6fe6d90d0e9306c20ad9385491aed19337
pdf-font-stream PDF embedded font (sfnt) at offset 0xCD0E 5300 bytes
font_01_sfnt_off0000df0c.bin
493af6d021c838d3fd4f8d6e3b78a0afaa743d3ac196e41e780ca92b14043e4f
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF0C 10472 bytes
font_02_sfnt_off000102cb.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x102CB 4324 bytes