Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd0ae365a55d04fb…

MALICIOUS

PDF

77.8 KB Created: 2021-04-02 22:15:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3ef3bb4f415ccaabc5b4ae4eed9b83b0 SHA-1: 39af634989450e0238e212debaec6751c7efd3dc SHA-256: fd0ae365a55d04fb43fa16f386758d7cd5b6689197af9c0801445d8ca787ffe9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain, likely intended to trick the user into downloading a malicious payload. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing or trojan PDF. No scripts were extracted, but the presence of an external URI is a strong indicator of a phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=emotional+intelligence+by+daniel+goleman+book+pdf
    • https://cdn.sqhk.co/faserekino/cppgeif/zisizaxologogeg.pdf
    • http://tukazijib.22web.org/99254110097.pdf
    • http://nitafibejuze.mygamesonline.org/characteristics_of_personality_disorders.pdf
    • http://mojenisijita.mywebcommunity.org/determination_of_coefficient_of_consolidation.pdf
    • https://cdn.sqhk.co/budajawisore/dl9eKgh/gacha_life_outfit_ideas_aesthetic_girl.pdf
    • https://cdn.sqhk.co/jifigetuxu/Chdiaia/1322696134.pdf
    • http://bududusawuwepi.iblogger.org/49849003341.pdf
    • http://midimox.getenjoyment.net/paradise_lost_summary_and_analysis.pdf
    • https://cdn.sqhk.co/lajawawinu/hjjisgf/my_electric_meter_has_gone_off.pdf
    • https://cdn.sqhk.co/lotidonita/jAsTHRu/20_levels_manchester.pdf
    • http://surozofawowidom.scienceontheweb.net/fuwulaliwupesutet.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6ba7316d-b84b-4ccb-a32a-103c856d4013.filesusr.com/ugd/91f37e_3837320c872541cc9bd1b4abb0cd0763.pdf?index=true
    • https://s3.amazonaws.com/fefurorobumi/kanawha_county_schools_wv_pay_scale.pdf
    • http://viwaneb.rf.gd/47463210605.pdf
    • https://uploads.strikinglycdn.com/files/456f030a-a2e9-4773-b779-6bc336235f5a/52396872724.pdf
    • https://679cd94f-bb1f-411a-9684-d99498fe93d6.filesusr.com/ugd/ce16d4_33574cf98ece4ddc8e84eff275f5fb3d.pdf?index=true
    • https://s3.amazonaws.com/fuwuzerijofa/dosomiwomoteze.pdf
    • https://90ff81fc-98d9-4e53-96a3-aaa5c1c2042e.filesusr.com/ugd/bb5aff_e0cdc09c98054c3c8ecb9383b8c0f366.pdf?index=true
    • https://uploads.strikinglycdn.com/files/47439280-336f-4210-a61e-db4876d5c8f8/what_is_the_moral_lesson_of_a_christmas_carol.pdf
    • http://zadosaw.epizy.com/wasibobilelebisopaki.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f15d.bin
057cc060a13bc0c69db96eb587b4e538c096cc9240a25caf443e84130986246b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF15D 5464 bytes
font_01_sfnt_off000103f2.bin
6816d93cf6e5c01b4250c098287339bb383d1efe5532733810b43197e67a54f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x103F2 11016 bytes