Malicious PDF — malware analysis report

Static analysis result for SHA-256 0eee1e5085b3aa56…

MALICIOUS

PDF

198.0 KB Created: 2021-03-21 23:20:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 62a35093ff20c0693c95b45071581562 SHA-1: 5c0951a54b548460cd6ec0bd282d92f21c6cc58a SHA-256: 0eee1e5085b3aa561b48845e6401f55ecef985d4cb6b4cc225e034687353ef6b
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as a malicious PDF by ClamAV and an ML classifier. Heuristics indicate it uses an advance-fee scam lure, presenting language associated with lotteries and prize claims. The document body, though truncated, contains metadata suggesting it was generated by wkhtmltopdf, and it embeds external URLs, one of which is associated with a keyword search, potentially leading to further malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9966

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=busybox+apk+xda
    • http://alexsaf.ru/leguvimerekukancfxeg.pdf
    • http://mailedflkf.site/how_to_write_a_5_paragraph_essay_examplexg5mj.pdf
    • https://static.s123-cdn-static.com/uploads/4479213/normal_5fe5cf7947438.pdf
    • https://static.s123-cdn-static.com/uploads/4451561/normal_5fe5ec2b68504.pdf
    • https://static.s123-cdn-static.com/uploads/4404105/normal_5fd088bcde2d4.pdf
    • http://austritkfa.com/7628506423vflml.pdf
    • https://static.s123-cdn-static.com/uploads/4460243/normal_5ff25da093ad2.pdf
    • https://cdn.sqhk.co/wifopuzuxiba/iLl2ljd/cute_love_stickers_for_whatsapp_ios.pdf
    • https://cdn.sqhk.co/ributexovek/ghcgghR/push_and_pop_using_array_in_javascript.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/sosupejuxofedo/algebra_2_answers_2019.pdf
    • https://s3.amazonaws.com/toliwudalamem/20597613124.pdf
    • https://s3.amazonaws.com/lupuvogotog/waledutugo.pdf
    • https://s3.amazonaws.com/bawalidamovidud/16896639535.pdf
    • https://s3.amazonaws.com/juzewojavomofew/decimal_word_problems_worksheet_grade_6.pdf
    • https://s3.amazonaws.com/rujabepifar/37347409377.pdf
    • https://s3.amazonaws.com/kelukakeb/what_does_the_word_firmament_in_the_bible_mean.pdf
    • https://s3.amazonaws.com/sisaxu/72100576040.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002b56c.bin
9e2514336c3153b9acd367a6e1546478a30d05415d6c305a0ed9643668c2a506
pdf-font-stream PDF embedded font (sfnt) at offset 0x2B56C 5248 bytes
font_01_sfnt_off0002c764.bin
03e810799b030fce918e2a108a043ebccaab7a0f44840d9f175c0de4415a9967
pdf-font-stream PDF embedded font (sfnt) at offset 0x2C764 12688 bytes
font_02_sfnt_off0002f290.bin
913105042ea274a8ab998f4913f19c0f71a88be1a153316284e266c5d665ac2e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F290 16568 bytes