Malicious PDF — malware analysis report

Static analysis result for SHA-256 0865d35965c08906…

MALICIOUS

PDF

143.6 KB Created: 2021-03-25 07:53:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: d9e2fb843f2c6a11402694da62c58fd3 SHA-1: 86bd4a861dd08c9a3865795247d0d43bf3594959 SHA-256: 0865d35965c0890601efebeda7aa117a17a5eeaceab806bb8fac0cf9cb7b35a0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=rehraas+sahib+lyrics+in+hindi PDF link annotation
    • http://jedusajinud.mygamesonline.org/when_dimple_met_rishi_netflix_cast.pdfIn PDF document text
    • http://lifolibi.sportsontheweb.net/anteprima_panini_336.pdfIn PDF document text
    • https://cdn.sqhk.co/nerenina/jjisgf0/jobosogale.pdfIn PDF document text
    • https://cdn.sqhk.co/fosojatesog/jbljhaI/deemo_reborn_pc_gameplay.pdfIn PDF document text
    • http://zagozogenef.sportsontheweb.net/biology_notes_for_class_12th.pdfIn PDF document text
    • http://bumumapa.mypressonline.com/pivuri.pdfIn PDF document text
    • http://pidusejop.medianewsonline.com/oreck_air_filter_cleaning_instructions.pdfIn PDF document text
    • http://vutisonoj.sportsontheweb.net/back_pain_exercises_arthritis_research_uk.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://s3.amazonaws.com/kakekojezutok/what_is_coming_to_netflix_in_january_2021.pdfIn PDF document text
    • https://s3.amazonaws.com/votubukaxogilix/80812991454.pdfIn PDF document text
    • https://s3.amazonaws.com/risalenefazozo/15478978595.pdfIn PDF document text
    • https://s3.amazonaws.com/fosagoba/gexewevewitoxux.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6011b620-f1d5-48ae-8390-9074137f89f3/luzikululuvawetoj.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9dc9360b-f63b-4ab1-8fc1-b35e39d8eb05/how_to_write_text_in_form.pdfIn PDF document text
    • https://s3.amazonaws.com/xetasif/jexobika.pdfIn PDF document text
    • https://s3.amazonaws.com/pulavokaxe/second_coil_of_bahamut_savage_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/mevuzokekenojab/64219530888.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3eee44ab-dae6-417d-9628-1ecbd75113ac/if_he_hollers_let_him_go_1968.pdfIn PDF document text
    • https://s3.amazonaws.com/bejideba/81661435583.pdfIn PDF document text
    • https://s3.amazonaws.com/vatakefojunib/adaptation_worksheet_7th_grade.pdfIn PDF document text
    • https://s3.amazonaws.com/bisapovepizaj/gukivusom.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/713ab9fe-5523-4953-bdf5-e154bf325df8/69798429293.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b0ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B0AE 5276 bytes
SHA-256: 8ef8e751d07108d0cc8000825e6ec3438a1b3e8337ce78e7d4a42e6c5f67b0c8
font_01_sfnt_off0001c299.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C299 3740 bytes
SHA-256: 6ce3ed3d0cf168fbf74d6eb321148d5efc31cda11559831b77020f7d4c9f4c8c
font_02_sfnt_off0001ce13.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1CE13 2328 bytes
SHA-256: 6b03cdd6ef0e880dc69d28376e3f1a44203d18faca3f96cdff4786a3927bd1e1
font_03_sfnt_off0001d836.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D836 10996 bytes
SHA-256: d953eac57db5801aa63cb9a55264213fb559031b83535b2f0391e041d4600855
font_04_sfnt_off0001fdec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FDEC 17588 bytes
SHA-256: 17de04f1c400c5e1fda4870702e94aa1651b5c01e4e589dc84f5d3b9e0422838