Malicious PDF — malware analysis report

Static analysis result for SHA-256 fdf3e01559d678d9…

MALICIOUS

PDF

85.4 KB Created: 2021-04-27 18:59:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6a88a64e73fb4a0c3fd1d0762398e7ed SHA-1: 2e6aab845a146c0a78baf5edac44d2077e4c0f02 SHA-256: fdf3e01559d678d970c3e02c2a5fb9bcb2fef5c10a70b1e9a8b06f344ca45201
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing multiple embedded URLs, one of which is flagged as malicious and likely serves as a lure for further malicious downloads. The ML classifier and ClamAV detection strongly indicate malicious intent, consistent with phishing or malware distribution. No scripts were extracted, but the presence of suspicious URLs suggests an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=gurps+powers+pdf+download
    • http://mobeditobaxul.scienceontheweb.net/boolean_algebra_and_switching_circuits.pdf
    • http://xelasurugopu.mywebcommunity.org/flowers_for_algernon_play.pdf
    • http://leyloften.online/coleman_lazy_spa_pump_wont_turn_on610bd.pdf
    • http://svoytrylend.xyz/zikawenawuzujazivunimawupzp.pdf
    • http://teksalle.xyz/bona_fide_request_formsr3jk.pdf
    • http://zitarekatinupas.sportsontheweb.net/effective_delegation_skills.pdf
    • http://com-signto2.xyz/32179222538jf8ry.pdf
    • http://xafesuvorolivig.scienceontheweb.net/xelinimek.pdf
    • http://zokugorevat.mywebcommunity.org/trn_c_tho.pdf
    • https://cdn.sqhk.co/juvanejejuwo/hajgQmM/potadexotutube.pdf
    • https://cdn.sqhk.co/letarezetap/glkiijh/37947139217.pdf
    • http://my-favshopf.online/servicios_en_red_mcgraw_hill_descargarqisb8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/239554c3-5037-4b41-b1ca-5be4f31cbd7d/free_download_adobe_dreamweaver_cs6_trial_version.pdf
    • https://s3.amazonaws.com/wewuxuviwar/orbit_battery_operated_sprinkler_timer_with_inline_valve.pdf
    • https://uploads.strikinglycdn.com/files/e280e1f5-bf19-4b49-b07d-54df7d3b9ac5/kigama.pdf
    • https://uploads.strikinglycdn.com/files/2721e9ce-e504-4add-9e46-1781222b4e99/septa_route_48_bus_sunday_schedule.pdf
    • https://s3.amazonaws.com/rekorewexidiwo/modejilodobedumu.pdf
    • https://uploads.strikinglycdn.com/files/a548757a-5e5f-4d56-afae-2baaff8066b6/nipiralad.pdf
    • https://uploads.strikinglycdn.com/files/e2f3d9f1-c1d2-4eb7-9158-4669dbbc89d3/romeo_and_juliet_1996_full_movie_free_123movies.pdf
    • https://s3.amazonaws.com/zomuzigo/celulares_android_buenos_y_baratos_2019.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1f2.bin
6b281bcd34016e2aed79b82f1ac4edaf4edaa271a03c5711646048e198bc192d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1F2 5160 bytes
font_01_sfnt_off000103a4.bin
f0ec28abb58842117e9eb078e9e8051c8babab7d26e5bb9fe5a5e6285a0518b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x103A4 13460 bytes
font_02_sfnt_off00012f03.bin
dfe1630aec38dcd3aef00611d735378144ae058dbcc59e5b57d42958d231205b
pdf-font-stream PDF embedded font (sfnt) at offset 0x12F03 17144 bytes