Malicious PDF — malware analysis report

Static analysis result for SHA-256 096cb5511fd1cad0…

MALICIOUS

PDF

69.7 KB Created: 2021-05-10 07:31:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 82d2b22f1663fae27469801ed0b13bf8 SHA-1: 2b7ded75378b27d56737489206a2b5216c7ebc64 SHA-256: 096cb5511fd1cad0e9336f19270c3473d25591d41283e83f3edc016ac0c6dd99
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains embedded URLs, some of which are flagged as unknown reputation. The ML classifier and ClamAV detection strongly indicate maliciousness. The document body, though heavily obfuscated, suggests a lure related to a 'Poodle size guide', which is likely a pretext to trick users into visiting malicious links for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://auxerretv.com/content/public/file/37552050658.pdf
    • https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1608dff3b1548e---mesosetesibopo.pdf
    • https://www.heainc.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075d2ebf3860---47131559847.pdf
    • http://www.theflightfest.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608413fc862ae---mitisirelasev.pdf
    • https://kfz-gutachter-oliver-schiller.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609411f34fa25---93224282072.pdf
    • http://hzjksj.com/images/upload/File/77247354985.pdf
    • https://absolut-fit-and-dance.de/wp-content/plugins/super-forms/uploads/php/files/g3gccotbgh8fi6dbbcbhjv7q2j/10094551574.pdf
    • https://alphaveneers.co.uk/wp-content/plugins/super-forms/uploads/php/files/79102e7daa4ee7d75a19ad5e9c5c3876/wogaruvosixifijuxisodel.pdf
    • https://vizzzio.ru/wp-content/plugins/super-forms/uploads/php/files/a2f01583013a5c2dd215e75bef8b7777/genokejuwerekadirukawetot.pdf
    • https://www.traveltimevipp.com/wp-content/plugins/super-forms/uploads/php/files/313bb09ed0c77132e3cfd465b4a99cab/ximetuto.pdf
    • https://www.sudburyhighspeedinternet.ca/wp-content/plugins/super-forms/uploads/php/files/9e3326e08cf109207398027306ddca2b/govimi.pdf
    • https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/4737bafde7592ae5b9cf0ba8cc5890c3/22541150229.pdf
    • https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/65e8d10d3a60d2af8c7661d71d7dbbec/27795159060.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://feedproxy.google.com/~r/skout/mBVl/~3/FevRqgeaUVY/uplcv?utm_term=poodle+size+guide
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cbb4.bin
ce2b180f0ce6eb68f56b5537175eb3f3263fec303576d0a01ff15eaf299f9ccb
pdf-font-stream PDF embedded font (sfnt) at offset 0xCBB4 4436 bytes
font_01_sfnt_off0000dacf.bin
b8c943a183c8dd8521ec4a244f92781da1a17a2dde909223fc720a7c4beb0120
pdf-font-stream PDF embedded font (sfnt) at offset 0xDACF 9824 bytes
font_02_sfnt_off0000fc6a.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC6A 4324 bytes