Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd877cb957d38684…

MALICIOUS

PDF

83.7 KB Created: 2021-04-01 13:54:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ffd029c5ecaf93d5dd479ff061a1b662 SHA-1: d68300567cefb330431569c2c346ddcdf675084f SHA-256: fd877cb957d386843d7c3a82384f063ea382d2552f02258c86cc23cd851e9c9d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an external URI pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also flagged this PDF with high confidence. The document body, though heavily obfuscated, appears to contain metadata related to the PDF's creation and the lure text, suggesting an attempt to trick the user into visiting the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=aspergillus+fumigatus+morphology+pdf
    • https://cdn.sqhk.co/ninilevikod/idiclep/love_breakup_sad_songs_free.pdf
    • https://cdn-cms.f-static.net/uploads/4493550/normal_60187d3728c82.pdf
    • http://labifovejes.mypressonline.com/2013_honda_civic_sedan_owners_manual.pdf
    • https://cdn.sqhk.co/xigofidiw/gjx0hjP/stay_alert_gummies.pdf
    • https://cdn-cms.f-static.net/uploads/4454054/normal_60625e3e68768.pdf
    • http://takipibimaxubov.sportsontheweb.net/begufarukunomawo.pdf
    • https://cdn.sqhk.co/kuwusemob/D8ifij3/27208998277.pdf
    • https://static.s123-cdn-static.com/uploads/4411483/normal_5fdd183e47bd0.pdf
    • https://cdn-cms.f-static.net/uploads/4375206/normal_604214144e1e2.pdf
    • https://static.s123-cdn-static.com/uploads/4408481/normal_5ffdfa30adafe.pdf
    • https://static.s123-cdn-static.com/uploads/4447271/normal_6004f5a5b4e8d.pdf
    • https://cdn.sqhk.co/gapalagabig/PjhJMjj/padepemepigutedawir.pdf
    • https://cdn-cms.f-static.net/uploads/4487192/normal_6038b9d20dd78.pdf
    • https://cdn-cms.f-static.net/uploads/4485451/normal_60145bdb978f5.pdf
    • https://cdn-cms.f-static.net/uploads/4460678/normal_603295217a7c1.pdf
    • https://cdn-cms.f-static.net/uploads/4501980/normal_604a936585349.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/vuxagixil/narrative_essay_example_college_students.pdf
    • http://kiluwemejibe.rf.gd/tascam_dr-05_mk2_review.pdf
    • http://bopiguxa.atwebpages.com/58014165500.pdf
    • http://popofisofol.myartsonline.com/martin_luther_king_i_have_a_dream_speech_full_version.pdf
    • http://kojomazudogog.epizy.com/free_printable_halloween_worksheets_3rd_grade.pdf
    • https://s3.amazonaws.com/xufujofaleki/92009565564.pdf
    • https://s3.amazonaws.com/wiremeresegikon/how_to_be_a_good_icu_nurse.pdf
    • https://s3.amazonaws.com/divelatoxa/health_and_safety_policy_document_nz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f943.bin
fe0fcbd575f1c0445e3bfff3bb607ed84e7acfc7b8ae254acee076bfe89fdb4f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF943 5320 bytes
font_01_sfnt_off00010b65.bin
c0ac222650cc940ce011ed57f4f3b8f70213f3ad5a2d3f63e96fc8a72bd332f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B65 11024 bytes
font_02_sfnt_off000130e9.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x130E9 4324 bytes