Malicious PDF — malware analysis report

Static analysis result for SHA-256 0ede9a08e8b931de…

MALICIOUS

PDF

85.6 KB Created: 2021-03-23 17:19:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9b016b734ea30c51072ac9778ec16961 SHA-1: d4bc55f372c4fc772446e0701496c6e60f4eb14f SHA-256: 0ede9a08e8b931de19c58ffad153e666597c50c69443db3ef5b82aea9de2bbe8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL disguised as a repair manual. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The PDF_URI heuristic points to the primary malicious URL used in the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=2020+bmw+x5+repair+manual+pdf
    • https://cdn-cms.f-static.net/uploads/4383470/normal_6042db67a1787.pdf
    • https://cdn-cms.f-static.net/uploads/4419002/normal_5fe6d99519268.pdf
    • https://cdn.sqhk.co/waxipefimafa/1rBighy/38543938994.pdf
    • https://cdn-cms.f-static.net/uploads/4368976/normal_600faea6d1fa7.pdf
    • https://static.s123-cdn-static.com/uploads/4389582/normal_5ffe8abfbfb14.pdf
    • https://cdn.sqhk.co/rapovebakeb/E6jgZie/74765053924.pdf
    • https://static.s123-cdn-static.com/uploads/4473954/normal_5ff08b3ae0795.pdf
    • https://cdn-cms.f-static.net/uploads/4420468/normal_600d15332c832.pdf
    • https://static.s123-cdn-static.com/uploads/4412763/normal_5fec7acb2546d.pdf
    • https://cdn-cms.f-static.net/uploads/4443325/normal_5fe7a7f9edc3b.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/7acbc8e9-61b7-4b70-8067-6a4fe506a523/sword_art_online_series_order_to_watch.pdf
    • https://uploads.strikinglycdn.com/files/58e810cb-7600-4ae5-8bec-0e60a47d8a9d/8155485447.pdf
    • https://uploads.strikinglycdn.com/files/3b871709-f59d-4eec-beb4-e15f1f96bec6/nibiwo.pdf
    • https://uploads.strikinglycdn.com/files/a65e4469-d31e-4d26-85a9-2818264188c6/zolizuku.pdf
    • https://uploads.strikinglycdn.com/files/0abb5854-f46e-4fa7-accf-845cf63225b4/crock_pot_slow_cooker_user_manual.pdf
    • https://s3.amazonaws.com/ladojenefe/badshah_telugu_songs.pdf
    • https://s3.amazonaws.com/woxewiwupir/3303387701.pdf
    • https://uploads.strikinglycdn.com/files/cd19097b-5566-4161-8edc-ad7507f01ee9/37090475450.pdf
    • https://uploads.strikinglycdn.com/files/7a288557-65b0-4d5d-97aa-d6c9121109ad/89817664903.pdf
    • https://s3.amazonaws.com/voxazedisula/52058405747.pdf
    • https://uploads.strikinglycdn.com/files/e61a17aa-21e3-43f1-8fbd-51f4024a6618/pajajumof.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001026c.bin
e0a6b576876ee49b48cab3ab969a3eb273e0bf4b3bcadae034ed2f5afbdbbe21
pdf-font-stream PDF embedded font (sfnt) at offset 0x1026C 5304 bytes
font_01_sfnt_off00011453.bin
cbedf9dd32c7e64862b63f0c4fce5349d8238fecb895e6a108e35cf941a80265
pdf-font-stream PDF embedded font (sfnt) at offset 0x11453 11256 bytes
font_02_sfnt_off00013aa6.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x13AA6 4324 bytes