Malicious PDF — malware analysis report

Static analysis result for SHA-256 016b511f5291b906…

MALICIOUS

PDF

151.6 KB Created: 2021-03-17 06:48:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9f512d3f998aad60dbfcbb55af9dc80a SHA-1: ec74223f32b8d426e0890bf467f17b34fda598ac SHA-256: 016b511f5291b90690a1b669601cdc67157bc61cecc6845deb768b91d69c60b3
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF document contains heuristics indicating it is a phishing lure, specifically prompting the user to install a browser extension or update. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the lure point towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/award?keyword=forever+living+probiotics+pdf
    • http://ijmalan.xyz/eggless_chocolate_cupcake_recipe_without_vinegarx0ubs.pdf
    • http://basiditdcf.space/30054247022928a7.pdf
    • http://autokenn.com/ethics_book_2k6mne.pdf
    • https://wopeduvolevim.weebly.com/uploads/1/3/0/7/130776212/5791477.pdf
    • http://axecheat6.xyz/xekazejurijidefivofasodp6zxt.pdf
    • https://konovupifa.weebly.com/uploads/1/3/0/7/130775136/9274916.pdf
    • https://vopoxeja.weebly.com/uploads/1/3/5/3/135346001/9932264.pdf
    • http://idealicaitalia-oficial.site/mystery_island_pokemon_glazedguuhe.pdf
    • https://jibunomo.weebly.com/uploads/1/3/5/3/135348462/patezujesutufepif.pdf
    • https://vunukufe.weebly.com/uploads/1/3/4/6/134640969/sonomosusuruku.pdf
    • https://fajevubesupuvax.weebly.com/uploads/1/3/5/3/135387480/8001297.pdf
    • http://mishabelle.ru/how_to_draw_a_turkey_using_your_handi5f8f.pdf
    • https://donefuvo.weebly.com/uploads/1/3/1/1/131164418/zevirowuxagib.pdf
    • http://thehensleys.org/335797354862r4pf.pdf
    • https://tidurikax.weebly.com/uploads/1/3/1/8/131856133/mitububidovudijo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://5548a280-a194-4776-8019-0e256783c1fa.filesusr.com/ugd/f2c1dc_c8dc652211354843836c44de21d97ea4.pdf?index=true
    • https://uploads.strikinglycdn.com/files/81db62b8-19ec-4366-931e-d9793cb1dc50/what_is_the_best_brand_of_enameled_cast_iron_cookware.pdf
    • https://f55c6975-0091-4942-a106-dc80285e5f9d.filesusr.com/ugd/8a4248_3d07c42960bb4cc2bb563bca3afd2bb5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a599749c-fc1a-45a4-8734-d57bdbcda718/soxulubilumomare.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f536.bin
1c998419a96e81ba21c105ad27608f97ab7947611d0345a0aefdee2b0e432981
pdf-font-stream PDF embedded font (sfnt) at offset 0xF536 98280 bytes
font_01_sfnt_off00021880.bin
7602c27a18a6126f8969dfa4b47daefe75efbdd7a6a4c95943ecafab5c4b553b
pdf-font-stream PDF embedded font (sfnt) at offset 0x21880 5268 bytes
font_02_sfnt_off00022a86.bin
9801d730a2de03e9e751f02abd6f59b1cbb851e0d4128a89949b89727edfc5cf
pdf-font-stream PDF embedded font (sfnt) at offset 0x22A86 11216 bytes