Malicious PDF — malware analysis report

Static analysis result for SHA-256 015ad23336dd5d3c…

MALICIOUS

PDF

80.0 KB Created: 2021-03-19 19:16:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2a13b6b404a0d06989fcebd27f0e2e32 SHA-1: e32a4595705978ab143e527b877c973af8f2fa52 SHA-256: 015ad23336dd5d3c02c0cfbc0a42c1b010a3fb4b73618bde7b1600635ac162b1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'dafemum.ru', which is likely part of the phishing lure. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect users to malicious content, potentially for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/123?utm_term=busy+busy+punjabi+song++mr+jatt
    • https://cdn.sqhk.co/lopijikuvi/gcyMiU1/cd_covers_free.pdf
    • http://migerov.xyz/56183017982rb2vu.pdf
    • https://cdn.sqhk.co/gapalagabig/bgh8icM/retro_bar_fridge_white.pdf
    • http://perfectiona.online/vex_iq_game_manualoju20.pdf
    • https://cdn.sqhk.co/xemugugafot/dsHgcja/cat_opening_mouth_gif.pdf
    • http://bitsracing.net/napuzilesrm8wj.pdf
    • http://natur-bio.space/nexuzawudud12twf.pdf
    • http://moitender.org/vermont_castings_defiant_encore_2190_review6igst.pdf
    • http://erogan24.website/kangana_video_song_freefzysh.pdf
    • http://getporte.xyz/pafolij9e7z3.pdf
    • http://tonagruz.ru/television_show_quiz_questionsvisd2.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://d1ced4a1-fa29-4c66-b583-77209f32159a.filesusr.com/ugd/c88d8b_16038aa443be443ebd57e6f1205a76b8.pdf?index=true
    • https://17a6c5a8-0587-4adf-8126-5b439e15a62f.filesusr.com/ugd/54bec1_0ee5729da7c74145a3c8973fecf42473.pdf?index=true
    • https://uploads.strikinglycdn.com/files/ae4b6c2a-dd28-4f4a-88cf-76ce623eb9b1/45071309620.pdf
    • https://s3.amazonaws.com/wizidimawag/febajabulilesadux.pdf
    • https://uploads.strikinglycdn.com/files/08a4a0be-8c21-46fd-9a78-deb0e2abccf9/luxubewujok.pdf
    • https://uploads.strikinglycdn.com/files/cf596c27-0af0-4469-95a1-c492ce817e69/is_there_a_weight_limit_on_carry_on_bags_southwest.pdf
    • https://uploads.strikinglycdn.com/files/55194f47-5951-4b27-8f7e-5f3f1adcf2bc/35576817741.pdf
    • https://uploads.strikinglycdn.com/files/3938da3a-8f84-4be3-a6c4-ab8235380e5c/unix_shell_scripting_learn_online.pdf
    • https://1ebfeea1-7d02-43b8-8f0a-002c87bc7f75.filesusr.com/ugd/50dcf6_66d2c0aa56a2452abffd3c4d5bebdf0f.pdf?index=true
    • https://s3.amazonaws.com/leributafa/emergency_wallet_card_template_word.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee6a.bin
23d727da3859ecf57534666a9624536a1bee4540d9f4dbbd9fc45c02f767ab2e
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE6A 5472 bytes
font_01_sfnt_off000100fe.bin
123b1ab14fb65fa98a494cb875f9718bd41ec25ef62475bfa64e60647bdfa566
pdf-font-stream PDF embedded font (sfnt) at offset 0x100FE 2504 bytes
font_02_sfnt_off00010be5.bin
fe75eb53480051479e5498b8bb1b3964a57fe16f97b03e4bd65ab368c28b5302
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BE5 11364 bytes