Malicious PDF — malware analysis report

Static analysis result for SHA-256 09cfa6f96e0f7385…

MALICIOUS

PDF

88.1 KB Created: 2021-05-10 23:04:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3058714b5f6f450805e53ff7f5654055 SHA-1: 6c02bd7bb041f1f6e7d75a402a3bfa69455aa371 SHA-256: 09cfa6f96e0f7385e0daa32b453ebe60588e6f0de247cd40396cd94cef2b2087
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an external URI pointing to a suspicious domain, identified by ClamAV and a machine learning classifier as malicious. The document body, though heavily obfuscated, contains text related to refresh rates, suggesting a lure. The presence of an external URI indicates an attempt to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/strik?utm_term=lg+refresh+rate+100hz
    • http://woxuruko.medianewsonline.com/gebamigerawivan.pdf
    • http://fejazeluxuz.22web.org/alice_in_wonderland_tagalog.pdf
    • http://mibikazut.mypressonline.com/25903286668.pdf
    • http://wokanetavim.iblogger.org/47217502848.pdf
    • http://zejirejajedudu.getenjoyment.net/51227366228.pdf
    • http://pametuwujikedag.iblogger.org/remington_700_sps_.270_win._24_bolt-action_rifle.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/9d362638-e226-489a-b648-69819fdf7e8f/48241654792.pdf
    • http://wadatenut.rf.gd/xuminuso.pdf
    • https://uploads.strikinglycdn.com/files/1652b8f5-783a-434d-9edb-54537923b6f9/rosemount_3051_datasheet.pdf
    • http://fukevitadej.epizy.com/80697870809.pdf
    • http://vafotuneg.rf.gd/notakibagoxaxexo.pdf
    • https://uploads.strikinglycdn.com/files/2a00dcde-3973-46e7-9d77-a932462dbcc6/how_to_build_a_moonshine_still_step_by_step.pdf
    • http://debarunuzijabe.rf.gd/activinspire_promethean_free.pdf
    • http://vawolanuxoreg.epizy.com/lilasilelotak.pdf
    • http://siroluga.epizy.com/32599414929.pdf
    • http://nowivopikuzud.epizy.com/diagnosis_of_hepatitis_c_virus.pdf
    • https://5fa60de5-32ab-41ac-ba65-77330e21e623.filesusr.com/ugd/2e16aa_ec5a8132c2584b599eb65185be7e2b04.pdf?index=true
    • http://dofavopuberobot.epizy.com/augmentative_alternative_communication_android_app.pdf
    • https://72858ab8-d36f-4bc2-b208-e5ec56e76d01.filesusr.com/ugd/3a4e0e_4fd0b583037341c7a67e217a0c004334.pdf?index=true
    • https://uploads.strikinglycdn.com/files/496447a0-3f7a-4cdc-adbc-e5d6cf52d246/winow.pdf
    • https://d45380bd-a93d-4ef2-b2bd-4c7806d1f6db.filesusr.com/ugd/5d2cf3_6280458a561d41e3b0f9ec2914f8dcec.pdf?index=true
    • https://80172413-d145-4b71-b7cf-4a007d76ad29.filesusr.com/ugd/cacfd7_e6e6bee2f6054fd6bb100fdcc9fccf1c.pdf?index=true
    • http://bojivudotafaf.epizy.com/75993410555.pdf
    • http://tomunipi.rf.gd/ralifakonadon.pdf
    • http://nuxotupasi.rf.gd/divad.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010bba.bin
4ca9019cb7c519b7a15425337f349d244edaaa8d4d2b14f8611de4fc453724e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BBA 4708 bytes
font_01_sfnt_off00011bd6.bin
b22109cc21ab735ef8d580866143fd4cf4abdf9ab862acf21f21e714ac4e6fd7
pdf-font-stream PDF embedded font (sfnt) at offset 0x11BD6 11568 bytes
font_02_sfnt_off00014309.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x14309 4324 bytes