Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6471cebaae1fc15…

MALICIOUS

PDF

67.8 KB Created: 2021-05-06 14:18:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d136932e2c4bd63dc2d7d802f5663638 SHA-1: d051adb737a9528c9338b9780e6c93fdc6b34c86 SHA-256: f6471cebaae1fc15db5ebe8743dbc2545ae2e0f2a7bf490aa6d9e285af6bc338
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains embedded URLs pointing to potentially malicious PDF files, suggesting it is part of a phishing campaign. The document body, though heavily obfuscated, indicates a lure related to 'expense sheet format free', aligning with phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://travels-ukraine.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c12aa04661---33597272527.pdf
    • https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c8fc593f91---wabijuxiwo.pdf
    • http://bubblesoflove.net/wp-content/plugins/formcraft/file-upload/server/content/files/160838830bbd33---tododaneloxasejitum.pdf
    • http://www.patricktennis.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607d11e48134e---50382688670.pdf
    • https://aimhc.com/userfiles/file/28177327156.pdf
    • http://www.kmclogistics.com/wp-content/plugins/super-forms/uploads/php/files/5d27740d6f6506e8e4b945e935b49eee/tawadadixom.pdf
    • http://www.nbrownies.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1606d2ced1dfd2---39272578665.pdf
    • https://www.lowdoc-loans.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160740326c8821---jetezifinat.pdf
    • https://cal.lighting/wp-content/plugins/super-forms/uploads/php/files/2e1b968b9a14a68d3002375f6227abfe/dijusubil.pdf
    • http://www.viksexteriors.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc66a2f82e---55027436462.pdf
    • https://markzone.az/wp-content/plugins/super-forms/uploads/php/files/jiip6u3cnh0oc9lqhbgliq42sg/tuvujanugasatasoropowowug.pdf
    • https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/160817e84243a8---zebuvezorusepulexovulog.pdf
    • https://www.lipfish.no/wp-content/plugins/formcraft/file-upload/server/content/files/16093387ee120e---55433433356.pdf
    • https://www.pharmaright.ca/wp-content/plugins/super-forms/uploads/php/files/4imhlh5ueuk8je5jouck97lktq/suvilejobumegugubupux.pdf
    • https://www.a2zmedical.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16073a6c8b6058---vebot.pdf
    • https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/c07dd4b1af23d278e244d2141e0ae38b/53716453820.pdf
    • https://eandjfamilyhealthcenter.com/wp-content/plugins/super-forms/uploads/php/files/87992ad5e0dc70e95e166e0cd7fca9e6/bitelixazikojuzuxadelisar.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/Uplcv/~3/Om9ozkHLxGw/uplcv?utm_term=expense+sheet+format+free
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cd93.bin
3b4bee4484407e9a3863c36b7732e726076d0cd7ff77bc64b0e2df2d11f3fd8f
pdf-font-stream PDF embedded font (sfnt) at offset 0xCD93 5136 bytes
font_01_sfnt_off0000dee5.bin
2f85c03853799f4f3b9d2a9c87e02858266620fa635319925d838bb54043153f
pdf-font-stream PDF embedded font (sfnt) at offset 0xDEE5 10396 bytes