Malicious PDF — malware analysis report

Static analysis result for SHA-256 fde29ee2992121b1…

MALICIOUS

PDF

79.5 KB Created: 2021-04-02 03:52:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 40c4263e782c08e9b34a7d3dd31b3897 SHA-1: 28fffc1141a64149fc7c4216b4803c90272d9fc7 SHA-256: fde29ee2992121b115292f8458c28187d1c21e3625da49bbc56a16b067318e7a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a malicious URL, which is a strong indicator of phishing or malware distribution. The ML classifier and ClamAV detection further confirm its malicious nature. Although no scripts were explicitly extracted, the presence of external URIs suggests the document is designed to redirect users to potentially harmful content, likely for credential harvesting or further malware deployment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=realidades+1+capitulo+6b+answers+page+112
    • http://bexemusu.mypressonline.com/86936615583.pdf
    • http://dosubodanes.mypressonline.com/palmers_olive_oil_formula_smoothing_shampoo_review.pdf
    • https://cdn-cms.f-static.net/uploads/4406793/normal_60378ff9eda3b.pdf
    • http://dsv-trening.ru/cube_method_for_strongman_reviewf6lep.pdf
    • https://cdn.sqhk.co/girolivudafo/dyihR5E/foponor.pdf
    • https://cdn-cms.f-static.net/uploads/4402032/normal_60334e1cd4c9e.pdf
    • https://cdn.sqhk.co/dugelabomaw/iHihBPc/nbc_sports_network_schedule_for_today.pdf
    • http://kerosijuvibeg.scienceontheweb.net/bobagemeza.pdf
    • http://floradoma.net/is_premier_protein_shake_lactose_freespyp4.pdf
    • http://getcreditreport.info/2020_honda_accord_hybrid_maintenance_schedulelun6k.pdf
    • http://latencfsrt.space/how_to_remove_the_front_of_a_whirlpool_washing_machinezt61d.pdf
    • https://static.s123-cdn-static.com/uploads/4404107/normal_5ff7759df1abc.pdf
    • https://cdn-cms.f-static.net/uploads/4408476/normal_5fe780d0b6497.pdf
    • https://cdn-cms.f-static.net/uploads/4380536/normal_601837dc9fe34.pdf
    • https://cdn.sqhk.co/faxiwapa/HigTMjh/triple_scoop_ice_cream_strain.pdf
    • https://cdn-cms.f-static.net/uploads/4450040/normal_603781a1a8763.pdf
    • http://idealica-uficialeitalia.website/51928401990195q4.pdf
    • http://visionnew.xyz/58673643910pu2zn.pdf
    • https://cdn.sqhk.co/mujawiru/hbvgjqA/amtrak_auto_train_bedroom_cost.pdf
    • http://myyshooop227.site/87031873276o5mlm.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://vakizonozajaxe.onlinewebshop.net/40220108471.pdf
    • http://dapizodipe.myartsonline.com/biografia_walt_disney_livro.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb76.bin
175231481316e143bc0eae2ec706428558ac028d9de6510eae575cacbb6252f5
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB76 5700 bytes
font_01_sfnt_off0000fef8.bin
24342eab7017abb92a22c5a58a5afe3ee0632b5f30f0da58ab28dd9855cdb8a0
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEF8 10376 bytes
font_02_sfnt_off00012264.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x12264 4324 bytes