Malicious PDF — malware analysis report

Static analysis result for SHA-256 f84f1e0aca4b78d6…

MALICIOUS

PDF

76.7 KB Created: 2021-05-13 16:15:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 211d751519e563d7b009e20b697b1323 SHA-1: 2e48ae24a4534719f29631230102a17a87903cb1 SHA-256: f84f1e0aca4b78d60591aa8b0880b9cdd2c148143b271ba143f3e3495c6faaa5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded URLs that likely lead to malicious content, as indicated by the ML classifier and ClamAV detection. The document's content, though heavily obfuscated, suggests a phishing lure related to an 'attending physician statement form'. No scripts were extracted, but the presence of multiple external URIs points to a downloader or phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/uplcv?utm_term=attending+physician+statement+form+york
    • http://baanpowertrain.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ce15945dfb---jagolelefejofaxiwebopixex.pdf
    • http://endustriyelkiralama.com/wp-content/plugins/super-forms/uploads/php/files/qb9p8ngvah0q47efue10qr432m/96348178285.pdf
    • http://www.argentum.com/wp-content/plugins/super-forms/uploads/php/files/pieh1pukjsgcppngjg4j8hdirl/20627443504.pdf
    • http://elonsummerstorage.com/wp-content/plugins/formcraft/file-upload/server/content/files/160740920c8eb0---kufupofu.pdf
    • https://universal4shipping.net/userfiles/file/66860410187.pdf
    • http://www.gradur.ba/wp-content/plugins/formcraft/file-upload/server/content/files/1607e7f1f893c8---81729704211.pdf
    • https://www.corridar.com/wp-content/plugins/super-forms/uploads/php/files/vnbkvj4e2qlm2ut6sj5d1bucuf/sotosojakukalatam.pdf
    • http://israel-aliya.com/wp-content/plugins/super-forms/uploads/php/files/6141262d9110f22b5cc7ce5d0388a7ac/43303441543.pdf
    • http://asianaccounting.com/admin/fckeditor/userfiles/file/gijudijalesik.pdf
    • https://simovi.mx/wp-content/plugins/formcraft/file-upload/server/content/files/1608a8f69eab20---xisafepivelifesimekasaw.pdf
    • http://www.marsagri.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609129fd1a2c3---52699795494.pdf
    • https://angkoronetour.com/userfiles/file/44386330115.pdf
    • https://aspirans.com/files/file/21687408997.pdf
    • https://eyestech.in/wp-content/plugins/super-forms/uploads/php/files/oihq19d1jns72tf14u2os9ov4j/24648214384.pdf
    • http://www.tif.cn/wp-content/plugins/super-forms/uploads/php/files/3bd9rfj8nmm7n6ne80d9929nlu/mazozo.pdf
    • https://iescolumbus.org/wp-content/plugins/super-forms/uploads/php/files/65a3cd32f094185eaef498411d54b981/30748228446.pdf
    • https://plswa.com/wp-content/plugins/super-forms/uploads/php/files/2ed435b42b420d58f349b70ffe660cab/19189251266.pdf
    • http://drinkandshrink.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160712f1f4a09e---97021797024.pdf
    • https://www.sgestrecho.es/wp-content/plugins/formcraft/file-upload/server/content/files/1607ea70be9a39---pesunerevokidusifope.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000de36.bin
c67970e12f15f123bba83adb3d0f665f59ad0b54d31c75fd7a5c77e5dd2d885e
pdf-font-stream PDF embedded font (sfnt) at offset 0xDE36 5480 bytes
font_01_sfnt_off0000f0b4.bin
4fcf00a2b9a3d5dbdc301fd9aa35d313dc3cebf3341cc4d498432bf9e41f6527
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0B4 10704 bytes
font_02_sfnt_off00011549.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x11549 4324 bytes