Malicious PDF — malware analysis report

Static analysis result for SHA-256 0750e32e46677317…

MALICIOUS

PDF

78.2 KB Created: 2021-04-27 10:53:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c2a2617a92f16f2ce9de3f3e2ef9b0f4 SHA-1: d5341f111383e034727a4d0e0b7189c961dffaff SHA-256: 0750e32e46677317923ccea471130977ecafdfcccae7d55c6bfccc905a03c758
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The file is identified as malicious by ML classifiers and ClamAV, with a high-risk score. The 'SE_CLIPBOARD_COMMAND_LURE' heuristic indicates the document instructs users to paste content into a command-line interface, a common tactic for executing downloaded payloads. The embedded URL suggests a potential download source for a second-stage artifact.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=allen+bradley+panelview+plus+600+configuration+mode
    • https://cdn-cms.f-static.net/uploads/4403946/normal_5fd11a0d99cc8.pdf
    • https://cdn-cms.f-static.net/uploads/4451929/normal_60662589c635d.pdf
    • http://jolixasij.sportsontheweb.net/what_do_circuit_symbols_mean.pdf
    • https://cdn-cms.f-static.net/uploads/4419818/normal_5fd979f2a23a1.pdf
    • https://cdn-cms.f-static.net/uploads/4460981/normal_5fdbbed95b2db.pdf
    • https://cdn.sqhk.co/junukexad/bghGifn/58314934816.pdf
    • https://cdn.sqhk.co/telapunojawu/bjiRguR/red_ball_evolved_level_2.pdf
    • https://cdn.sqhk.co/limiwebu/Eggjhgd/36793554915.pdf
    • https://cdn.sqhk.co/mubafazus/fTbifif/baltic_birch_plywood_sheet_sizes.pdf
    • http://nazorizuz.medianewsonline.com/ikan_demersal_adalah.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fekife/ge_quality_product_spacemaker_laundry_manual_espaol.pdf
    • http://rowoniwetob.atwebpages.com/cassava_production_in_thailand.pdf
    • https://uploads.strikinglycdn.com/files/9cd2379f-73f0-40a1-8b1b-0587d60528da/bubupobubijapi.pdf
    • https://uploads.strikinglycdn.com/files/0cf261b1-cd82-4620-94ef-de2e05ba3999/kejetasib.pdf
    • https://s3.amazonaws.com/pazatuv/5091885478.pdf
    • https://s3.amazonaws.com/wowonesoribu/sunemavok.pdf
    • https://s3.amazonaws.com/solonebosop/8303343508.pdf
    • https://s3.amazonaws.com/pujinit/zotebikivadapumobunijon.pdf
    • https://s3.amazonaws.com/remeranexe/51614887442.pdf
    • https://s3.amazonaws.com/petuzutemixuvod/zonuvisufubiwafodotilutu.pdf
    • https://uploads.strikinglycdn.com/files/52ee383c-8635-494e-be4f-fa882d25c4a8/how_to_write_a_good_novella.pdf
    • https://s3.amazonaws.com/vofadoloves/45535584426.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee49.bin
90c18bcd96f69d6b741617a60232fe61a0744c1b6cef714ae62dacf1fe048e40
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE49 6156 bytes
font_01_sfnt_off00010341.bin
732af6cd11f68e9360f8aac6d717bfe7002f74ca953771a6a6217beea50e6a93
pdf-font-stream PDF embedded font (sfnt) at offset 0x10341 11168 bytes