Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff925d33ffc17b18…

MALICIOUS

PDF

81.0 KB Created: 2021-05-26 01:30:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-05
MD5: 2503d20050e1e2fc6e3edee1e77fc8ab SHA-1: 536497e13447e6b906b584eaeb1f7dba99c7d8de SHA-256: ff925d33ffc17b181c70924d378b90bc72a000cdd5b5b165db543aa5ad3e3969
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL points to a suspicious domain, likely serving as a lure for phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and the presence of an external URI suggest it's designed to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=assistir+novela+os+dez+mandamentos+nova+temporada+capitulo+42 PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4421461/normal_603f1f326a4e1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4375195/normal_5ffea3c2cdae0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4471992/normal_6014f5b13a008.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455183/normal_601fc41a64724.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4486350/normal_605d988b180b4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4455176/normal_60125d3e6edf5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4458635/normal_5ff1dd522e000.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4482413/normal_601e4f4599578.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/e446e3ce-38d2-4f38-8ac1-2c9af7c12c81/traductor_ingles_espaol_gratis_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a732db2d-57cf-468d-95c1-c6a772987cab/96251176967.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5aff6d0a-d48a-4376-ae16-ba5efd457cc8/what_was_the_iron_curtain_and_how_was_it_a_factor_of_the_cold_war.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0a4696e6-4fb3-4f3e-b470-6b9ef24e45d4/propresenter_7_update_cost.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/52a76c3c-d8b1-407c-af8c-19e61ec98244/dipoxigitebi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/192f2e11-42f0-446b-866d-cac9116fa2f8/lomugetaxawibu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1d7bfef0-b400-42fd-88ff-85d48f0ceae1/engineering_drawing_assembly_example.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/06d14d3c-a25a-4bea-b686-b345a5b298d6/xefiledulozoxanob.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0fce8556-5e4d-4ef8-80c9-1406bb60f766/85886010760.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7f9076bc-4e8e-4822-9ba0-5e8fed0505f2/washington_state_unemployment_standby_extension.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f2b8740-edb2-414a-954b-20937c670cd1/boss_tu_3_vs_tc_polytune_2.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1a5c4d5f-ef92-42a1-b0df-bd80122abe00/basic_object_oriented_programming_concepts_c.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/98dc9776-abc8-4b62-98f8-08d2e4093d94/britax_car_seat_protector_nz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c6e41958-5c46-4dea-9cdc-8de9fda5fd96/how_does_the_last_book_of_the_after_series_end.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/83d09530-5792-4176-907b-6ba5cd8a378f/rekiselazabulivu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/29087a5b-f776-410f-953c-ef3787559973/jipisijivimibe.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5ea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF5EA 5540 bytes
SHA-256: 0e14bd3e1d63573517b62f15217364764149a2dc016a3f4e8d509ebc01f577b0
font_01_sfnt_off000108bd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x108BD 14292 bytes
SHA-256: 43df67d702e05c88228b44fad460b10212e4000f1c6a1f190af666c4529991b1