Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f49a3e52a5dfabe…

MALICIOUS

PDF

74.3 KB Created: 2021-03-15 18:27:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dc3a1ae9102dda473e287471e022d932 SHA-1: 29a11728e009d4fdbb81a4a7b3d84f8e6124dd8a SHA-256: 0f49a3e52a5dfabe06a3761ac0773ef9e673703d0261ca5120fb7467221a53dc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that mimics a search result for a free PDF download, likely serving as a lure. ClamAV and an ML classifier flagged this PDF as malicious, indicating it is designed to deliver a phishing or trojan payload. No scripts were extracted, but the presence of a malicious URL suggests an attempt to redirect the user to a compromised site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/wix?keyword=dark+psychology+101+pdf+download+free
    • https://cdn-cms.f-static.net/uploads/4387699/normal_604e814c9a695.pdf
    • http://ladyso.ru/chicco_keyfit_2_car_seat_coverzavl2.pdf
    • https://cdn-cms.f-static.net/uploads/4467027/normal_6045e72d0d96d.pdf
    • http://firejowetawo.iblogger.org/shortcut_keys_and_full_form_of_computer.pdf
    • http://nosinoski.shop/33331803640qw30i.pdf
    • https://sefufomoxuve.weebly.com/uploads/1/3/4/5/134528328/aafe6cce48.pdf
    • http://axecheat5.xyz/angel_care_baby_monitor_ac401_beepingvy0v9.pdf
    • https://kilekefaze.weebly.com/uploads/1/3/4/6/134631798/lubaxejituxibo.pdf
    • https://xusolufazajone.weebly.com/uploads/1/3/1/3/131383045/vibanafam.pdf
    • http://gufutaca1.xyz/hack_driver_answerscjgxj.pdf
    • https://cdn-cms.f-static.net/uploads/4422367/normal_5fea44fea5e82.pdf
    • https://cdn-cms.f-static.net/uploads/4471082/normal_5fd6741149d07.pdf
    • https://bibomezu.weebly.com/uploads/1/3/2/7/132710601/deviwixepa.pdf
    • https://bebemabuvi.weebly.com/uploads/1/3/1/4/131453051/fbf5ecc41db.pdf
    • https://cdn-cms.f-static.net/uploads/4408355/normal_604ed83929823.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://talidarufuji.epizy.com/building_commission_complaint_form.pdf
    • http://toxuwer.epizy.com/97390402792.pdf
    • https://0dd4521b-3e41-4083-9bcc-807cce03ae78.filesusr.com/ugd/cfe2e9_bf017f67a0ad4533b003dcb1c94a111b.pdf?index=true
    • https://s3.amazonaws.com/lopadivupudexa/graftech_international_ltd_annual_report_2017.pdf
    • https://s3.amazonaws.com/rijaliwiguvex/71519463593.pdf
    • https://s3.amazonaws.com/vinejivunitego/sense_sensibility_and_snowman_movie_youtube.pdf
    • https://72858ab8-d36f-4bc2-b208-e5ec56e76d01.filesusr.com/ugd/3a4e0e_ba5d852eb03646d28156f839aaa073d8.pdf?index=true
    • https://3a7b682b-4b85-4b21-836a-a34929c8735b.filesusr.com/ugd/0cd3a8_cb5c6ba75d03422dbbed9ed7acc70311.pdf?index=true
    • https://88211235-bf86-4d40-a6ec-a052db2f682e.filesusr.com/ugd/94e5ef_7f1a83e72a034fa89fe2c4e15c89fee1.pdf?index=true
    • https://s3.amazonaws.com/wenobagupexekap/duzitafafesubewififijel.pdf
    • https://s3.amazonaws.com/gumegulaxi/brewer_and_treyens_research_method.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e432.bin
5743235d99f7e52ec7fe30c046c7283919a63b92f3dfd49e410f20aa2b34a695
pdf-font-stream PDF embedded font (sfnt) at offset 0xE432 5868 bytes
font_01_sfnt_off0000f851.bin
4d109cc6a4016e80e1babbd575961c2b9de72c01a8296265763f75e19f96adfd
pdf-font-stream PDF embedded font (sfnt) at offset 0xF851 10184 bytes