Malicious PDF — malware analysis report

Static analysis result for SHA-256 fca478a934fd1a9f…

MALICIOUS

PDF

72.7 KB Created: 2021-03-23 19:14:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 38bfa3ef1a6f034406d9e0f097933010 SHA-1: d3df0abb6fa93871c56a5e134abb1738aac56214 SHA-256: fca478a934fd1a9f69b352a4adf1a3644760ca26276dec47aa072ed87c910c6c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The document body and embedded URLs suggest a phishing lure related to 'food stamps md income guidelines', directing users to external sites that likely host further malicious content or phishing forms. The presence of embedded URLs and the nature of the lure align with spearphishing attachment tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/123?utm_term=food+stamps+md+income+guidelines
    • https://cdn.sqhk.co/topefebi/ghchap9/20130252356.pdf
    • http://alcexpress3.xyz/how_to_reset_sony_xbrlw0a5.pdf
    • http://copyrighthelpcentral.com/how_to_become_a_successful_business_womanmd1l5.pdf
    • http://successinyourlif.website/namavuzigamujodimedibjwxg4.pdf
    • http://worelimupuvefam.mywebcommunity.org/cannon_landmark_fire_safe_costco.pdf
    • http://lnstgramhelpcopyright.com/63966228302b8t95.pdf
    • http://fakovaj.22web.org/rujemosusagajo.pdf
    • https://cdn.sqhk.co/boxokozofe/11jgPjc/vuvulevede.pdf
    • https://cdn.sqhk.co/ninulekuto/cN2gfji/kekixubobafupagureziwesub.pdf
    • http://zugawumaz.22web.org/aetna_better_health_of_pennsylvania_provider_manual.pdf
    • http://uabiomanix.xyz/684614826068elyu.pdf
    • https://cdn.sqhk.co/dizukenepu/cCohiUN/vidiq_chrome_extension.pdf
    • http://detonicinitalia.website/livro_de_direito_processual_civil_esquematizadoalomw.pdf
    • https://cdn.sqhk.co/nupozifulija/igijZgj/nitro_nation_drag_drift_apk_obb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/31bea0be-ee9c-4542-98e0-1695e400e6e2/why_is_my_dog_always_thirsty_and_peeing.pdf
    • http://sepinolet.epizy.com/pride_and_prejudice_1995_full_episodes_online_free.pdf
    • https://uploads.strikinglycdn.com/files/209cfd75-d2fb-4f79-a1c2-408387cfaa87/xejabiguzelagat.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df00.bin
01a4f6f52e31b28be07cf961172a2862f60bf257a6a744b52f2f94b878d40ab8
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF00 5252 bytes
font_01_sfnt_off0000f0d4.bin
75c6099ac427ebfa16c28e18040b393e40197f1a8b41f70b18482d2f3ab9fd06
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0D4 10884 bytes