Malicious PDF — malware analysis report

Static analysis result for SHA-256 fec0e51ab807bb52…

MALICIOUS

PDF

79.1 KB Created: 2020-11-25 04:41:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cc6fe27636fb781389f16132c00e9d5d SHA-1: 76352bf0af7de6f5b08aceb5ad7449f8cea6ecc0 SHA-256: fec0e51ab807bb526841434837fc6bd6a7a19f021df3c2a4a973db6cabb84e2d
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by a machine learning classifier and ClamAV, with heuristics indicating the presence of external URIs and an urgency lure. The document body, though heavily obfuscated, contains references to 'we the people' and 'wkhtmltopdf', suggesting a potential phishing or scam attempt. The embedded URL points to a suspicious domain, likely serving as a redirect to a malicious payload or phishing page.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=%25E2%2580%259Cwe+the+people%25E2%2580%259D
    • https://dujolisinapujis.weebly.com/uploads/1/3/4/3/134328324/925383.pdf
    • https://nakefofomiruni.weebly.com/uploads/1/3/4/4/134483242/727354.pdf
    • https://cdn-cms.f-static.net/uploads/4370547/normal_5f8ad36370c31.pdf
    • https://cdn-cms.f-static.net/uploads/4489598/normal_5fadac0d88db3.pdf
    • https://cdn-cms.f-static.net/uploads/4464523/normal_5fbda5cc7e1e1.pdf
    • https://givexikiduxa.weebly.com/uploads/1/3/1/3/131398224/8d5a24b.pdf
    • https://cdn-cms.f-static.net/uploads/4466376/normal_5fb0379d43480.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/a6eb6928-9c19-43ab-87d0-01feb098b1db/halsey_hopeless_fountain_kingdom_album_download.pdf
    • https://s3.amazonaws.com/fisulefajow/moxuvusozipomefarupajimew.pdf
    • https://s3.amazonaws.com/gaxuremewuger/fruit_and_insects_ruysch.pdf
    • https://s3.amazonaws.com/sugaguxagu/50465496785.pdf
    • https://s3.amazonaws.com/zarusegibitumet/aquamarine_full_movie_with_english_subtitles.pdf
    • https://uploads.strikinglycdn.com/files/14e57137-7596-435e-92f9-8461a79d9860/22389348474.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f81d.bin
231e0a71500984e66b7070cb603befdf189fd4ca4fcdccc18e91abb44a23ec6b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF81D 4596 bytes
font_01_sfnt_off000107c7.bin
68ce6817ef3ad22f45cdd7ebd8a9a690a4dc5df64bfbe28495343ab8574b0d22
pdf-font-stream PDF embedded font (sfnt) at offset 0x107C7 11224 bytes