Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e2225d7341343c0…

MALICIOUS

PDF

356.4 KB Created: 2021-04-17 11:12:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 0c54ad9dcb5a5dfb6e91605ab7be0c7e SHA-1: 2f60c25a615f62f972f5fdd3dc178998a01a9399 SHA-256: 0e2225d7341343c016a419106df9d8ef01c38b3fd2940a2a269ab5eb835a69dc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded URLs that mimic search results for product manuals, directing users to malicious domains. ClamAV and ML classifiers also flagged this PDF as malicious, specifically as a phishing trojan. The presence of embedded URLs suggests an attempt to redirect the user to a malicious site, likely for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7869

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=casio+5146+manual+espa%25C3%25B1ol PDF link annotation
    • https://cdn.sqhk.co/vibupiwoxaro/0Hjjhii/45271351607.pdfIn PDF document text
    • https://cdn.sqhk.co/reteduze/gccPoTR/kaxalolut.pdfIn PDF document text
    • https://cdn.sqhk.co/nozedimasav/7McA9hg/fotizixasakuvewadut.pdfIn PDF document text
    • http://zamirelerubonex.iblogger.org/75639437964.pdfIn PDF document text
    • https://cdn.sqhk.co/fapiwejagiz/iafVhbT/miranda_cosgrove_net_worth.pdfIn PDF document text
    • https://cdn.sqhk.co/nomuzali/fhdjedP/banana_monkey_game_download.pdfIn PDF document text
    • https://cdn.sqhk.co/rapovixovuti/wBjdhcY/nunapejiz.pdfIn PDF document text
    • https://cdn.sqhk.co/xosaletozobi/fgihiie/42939017697.pdfIn PDF document text
    • https://cdn.sqhk.co/zoluxoni/fhgfgca/39559835872.pdfIn PDF document text
    • https://cdn.sqhk.co/widafopaj/Ry0gejh/68585830960.pdfIn PDF document text
    • https://cdn.sqhk.co/fupupusamun/OBWidqQ/mode_sans_smp_mcpedl.pdfIn PDF document text
    • http://pijabaralipori.22web.org/30061956283.pdfIn PDF document text
    • https://cdn.sqhk.co/vatuliwa/gdkM01y/xopofodezeto.pdfIn PDF document text
    • http://sosunimepewe.22web.org/konar_tamil_guide_9th_free_2018.pdfIn PDF document text
    • https://cdn.sqhk.co/vemegunir/eijOgga/12764074954.pdfIn PDF document text
    • https://cdn.sqhk.co/razefudixid/iiieigx/3930817180.pdfIn PDF document text
    • https://cdn.sqhk.co/puvegipuros/fgfhehj/edge_of_oblivion_alpha_squadron_2_mod_apk.pdfIn PDF document text
    • https://cdn.sqhk.co/bisegepamitu/jigfhcZ/ffmpeg_loop_gif_to_video.pdfIn PDF document text
    • https://cdn.sqhk.co/pugepavofu/cha3shf/84703974874.pdfIn PDF document text
    • https://cdn.sqhk.co/ronelejibir/jbgcXgh/47471279057.pdfIn PDF document text
    • https://cdn.sqhk.co/delotijuw/jigigid/oxford_collocation_dictionary_online.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://08202b68-adf4-4b7d-bb06-fcebe54c78b8.filesusr.com/ugd/76dd3d_8365110b50f64883981558be3f2e5604.pdf?index=trueIn PDF document text
    • https://2a009ac4-5770-49f2-ae16-4ce107243443.filesusr.com/ugd/59deca_af762ee2a60a42bc8d68a6a4db761165.pdf?index=trueIn PDF document text
    • https://ea64ff4c-51e6-4efc-8cc1-399682447901.filesusr.com/ugd/961f18_258b78e72ae64fa9b6725f0adb69085b.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004ec06.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4EC06 6644 bytes
SHA-256: 0230468a10b28a2ff54ec3d81261fc4524aa83af666ce6e368f14134420a4a91
font_01_sfnt_off000502b4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x502B4 5324 bytes
SHA-256: 65dd977fa9c54114dff593f65e98c7ea9c996e4ce643a282fc1812e9caf83db1
font_02_sfnt_off00051472.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x51472 6500 bytes
SHA-256: 0462f2da062f19ad08a0c30be5bd108302f52a99d39e42e651f4355953040a3f
font_03_sfnt_off000525a7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x525A7 18244 bytes
SHA-256: b5cbc4a21e1ace58611a299607d5912b24cb504d601e1bab7dbbb6153d525b08
font_04_sfnt_off00055bd0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x55BD0 16084 bytes
SHA-256: ce90dcb8f80a691a226d66d7b9fb40db13b52946125f6d312f8860abae454107
font_05_sfnt_off00057090.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x57090 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3