Malicious PDF — malware analysis report

Static analysis result for SHA-256 f923d144d9dea389…

MALICIOUS

PDF

86.4 KB Created: 2021-07-02 05:56:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: c5ea6df8564fb726e1a467a77047fd3c SHA-1: 7a5c938821c96ea02a42f52c4b098c849320c29d SHA-256: f923d144d9dea3891a46f8ff2ad1c3a50162d03e5968a8b4b11b563765774fd2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of multiple unknown URLs suggests an attempt to redirect users to malicious content, likely a phishing lure. The PDF structure itself does not contain readable content, but the embedded URI heuristic points to a potential phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9848

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cf4a586a0f---bipifaguboluko.pdf
    • http://banlinhkienlaptop.com/userfiles/file/nukobivozepisaxi.pdf
    • http://www.cuadernos.in/wp-content/plugins/formcraft/file-upload/server/content/files/160de2d5d34e70---pidexozidadivadekovi.pdf
    • https://www.myjamaicais.com/wp-content/plugins/super-forms/uploads/php/files/7f106a78655bb87ffbacd417f59fe9ed/69168876689.pdf
    • https://grandplaza.bg/uploads/assets/file/badisuvofixuxoxuzudufixe.pdf
    • http://sanitaerprofi.ch/fckeditor/editor/images/file/gebegije.pdf
    • http://antifftech.com/uploadfile/file///2021050301214820.pdf
    • https://stcatherine.ac.ug/wp-content/plugins/formcraft/file-upload/server/content/files/160aad20df3914---80928738208.pdf
    • https://ahi.com.ua/wp-content/plugins/super-forms/uploads/php/files/33e8bb1bbe0eb09e306d298173f479b2/lotoniwatusawarolatunapi.pdf
    • https://saraelv.no/wp-content/plugins/formcraft/file-upload/server/content/files/160c6310138360---mivilodazenudafonafokaxet.pdf
    • https://syntellect.ru/Repository/file/50671941910.pdf
    • https://ncfouting.com/wp-content/plugins/formcraft/file-upload/server/content/files/160cc7c0756bc4---49031009912.pdf
    • http://nfraccon.org/userfiles/file/40410240403.pdf
    • http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/9u06h11ds0pk2ttq6tm08ehkb0/zasinovoxu.pdf
    • http://biswasi.com/userfiles/files/42278706534.pdf
    • http://stkvn.ru/wp-content/plugins/super-forms/uploads/php/files/3aafa154d5531fc2cd457e76d79c5970/silemo.pdf
    • http://gramercygrand.ru/files/file/virabubepolubewobiviju.pdf
    • https://jdrum-music.com/uploads/ckfiles/files/30372875059.pdf
    • http://k-yoga.org/file_upload/spaw_upload/file/20210503210509.pdf
    • http://refah4ter.info/basefile/hotelrefah4terir/files/68881710317.pdf
    • https://www.andyselfstorage.co.uk/wp-content/plugins/super-forms/uploads/php/files/tr5s17li9s7l5462cb7ftq3o4d/rerivirorosanon.pdf
    • https://apexforestservices.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a49d135486---banujubupori.pdf
    • http://www.kocay.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1607a07e022b7a---89279495708.pdf
    • http://bularz-auto.pl/images/userfiles/file/68374813644.pdf
    • https://fermuar.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d52f219e95c---20030506453.pdf
    • https://kompaspt1.com/contents//files/93831580185.pdf
    • https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=the+human+heart+includes+how+many+chambers
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000edcb.bin
185e425d939c8a29aba18a5534487d3df1f19acc9556c335c5ee4012035cde76
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDCB 11040 bytes
font_01_sfnt_off00010757.bin
8cbc9af87e7b75df6d85adcbc9d8a095b4831df60322a954a8a1c692f58e3434
pdf-font-stream PDF embedded font (sfnt) at offset 0x10757 17248 bytes
font_02_sfnt_off000133f5.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x133F5 16792 bytes