Malicious PDF — malware analysis report

Static analysis result for SHA-256 0d9b0249b10b4df5…

MALICIOUS

PDF

140.4 KB Created: 2021-03-10 17:56:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3a5d0ea773edb48e6a54bb15257b73ef SHA-1: 2a9afc65a198366c3089650b195ad55b1237e1ec SHA-256: 0d9b0249b10b4df5e164a950804ff74e66972d177e160ee4b97e42abb7ca9449
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF document flagged by ClamAV as a phishing trojan. Heuristics indicate it uses an advance-fee scam lure, attempting to trick the user with promises of prizes or funds. The document contains multiple embedded URLs, one of which is `https://xezojetit.ru/aws?utm_term=how+does+godfather+end`, likely serving as a malicious link or redirect.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/aws?utm_term=how+does+godfather+end
    • http://shtancircul.site/kedofixadutogon2rmjp.pdf
    • http://usejus.pro/6208087886120g04.pdf
    • http://junumidutuzakox.getenjoyment.net/which_engineering_course_has_more_job_opportunities.pdf
    • http://digitalliteracyinstitute.com/all_my_sons_arthur_miller_full_movieo00ud.pdf
    • http://pmaider.com/88536949593sl2cm.pdf
    • http://kujamemapevubu.mypressonline.com/11733861486.pdf
    • http://instapriz.site/190249190785f7un.pdf
    • http://dragonflysagewellness.com/jumper_clothing_british3n2kt.pdf
    • http://tonojodozif.mypressonline.com/lonekav.pdf
    • http://nulatapukedu.scienceontheweb.net/dilenepiwomiloxerumilurut.pdf
    • http://gsmall.space/chrysler_voyager_user_manual3e8gl.pdf
    • http://tasiperop.medianewsonline.com/joxorokotiziz.pdf
    • http://fupemagis.mywebcommunity.org/how_to_change_transmission_fluid_honda_accord.pdf
    • http://1xbets-regs.site/harry_potter_fanfiction_lemon_minervai33nm.pdf
    • http://bitcoinlearningcentre.online/science_vie_tv_izlee8ybr.pdf
    • http://vixemifojetinag.sportsontheweb.net/how_to_use_a_hamilton_beach_roaster_oven.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fepusum.onlinewebshop.net/assessment_tools_for_autism.pdf
    • http://wozimape.onlinewebshop.net/61467939666.pdf
    • http://tofalit.myartsonline.com/formulaire_declaration_de_cession_vehicule.pdf
    • http://zitasixan.atwebpages.com/fokoj.pdf
    • http://segurixuzek.myartsonline.com/bmw_navigator_v.pdf
    • http://kakasis.onlinewebshop.net/zefakoligaretagovamamaxe.pdf
    • http://tosurok.myartsonline.com/matulobawijegudexem.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001eaf9.bin
c86084f208148ce32e652e3686427593b152fc3827e335b5245cdc69ecb04787
pdf-font-stream PDF embedded font (sfnt) at offset 0x1EAF9 5192 bytes
font_01_sfnt_off0001fcad.bin
bf5cf8251ef22759dbb7a0d6d46de3a19426b5c8ca83a966260982edd56c8f61
pdf-font-stream PDF embedded font (sfnt) at offset 0x1FCAD 11716 bytes