Malicious PDF — malware analysis report

Static analysis result for SHA-256 0fc551077bcbff7e…

MALICIOUS

PDF

70.5 KB Created: 2021-05-15 06:56:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e3adb158b1b91241873ce8fb641ea5dd SHA-1: 23fe5246d4422b283f8d3bcdcb2fe622f9f1176e SHA-256: 0fc551077bcbff7edfc9fbff50ac40e91ffe174a13f8c5a615270b74dc719dab
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of embedded URLs, such as 'https://huntic.ru/uplcv?utm_term=advanced+algorithmic+trading+pdf', suggests the document is part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, appears to be a lure related to algorithmic trading, likely intended to trick users into downloading a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://huntic.ru/uplcv?utm_term=advanced+algorithmic+trading+pdf
    • https://discoverapartmentsforrent.com/wp-content/plugins/super-forms/uploads/php/files/78122ef38341fbd774a984985aed0364/zasowisakuxew.pdf
    • https://ecoinkworld.com/wp-content/plugins/super-forms/uploads/php/files/55ce1f54615b33b25d2f6fae5af4dedf/45035856541.pdf
    • https://betonwerkendejonge.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1606eb1e082fe4---99321081909.pdf
    • http://www.appsolutely.sg/wp-content/plugins/formcraft/file-upload/server/content/files/16084d4e4ebaf6---sevoxuredejodobuparikozo.pdf
    • http://conservationenergy.com/wp-content/plugins/formcraft/file-upload/server/content/files/160857d735a56e---geruzupokapujawo.pdf
    • http://anhuizpyy.com/upload_fck/file/2021-5-3/20210503080346312819.pdf
    • http://baanpowertrain.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608782fa4e614---sukipogepel.pdf
    • http://gennarimaq.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608007a268419---jivobuxonatasuziwonet.pdf
    • https://popa.com.br/wp-content/plugins/super-forms/uploads/php/files/b23176401c77321cefb2a5af460c203a/zofito.pdf
    • https://acgroupenterprise.com/userfiles/file/mewesibogokijojaw.pdf
    • http://heilpraxis-pankow.de/wp-content/plugins/formcraft/file-upload/server/content/files/160910c9ed4f25---69338581917.pdf
    • http://abapaposentados.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607fafd535483---zovaxedawo.pdf
    • http://www.tif.cn/wp-content/plugins/super-forms/uploads/php/files/i3grhd0ipq087guge3htkehtgm/22727157156.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d837.bin
03cd8e7a54b24b56766a9063bcb78f505f5e3e4ee7ff40c60b1564bcacdd83a1
pdf-font-stream PDF embedded font (sfnt) at offset 0xD837 5440 bytes
font_01_sfnt_off0000ea99.bin
ded8972031bec89384d9d445f8ee34b9c636bd0a239588b34834297091b2181b
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA99 10116 bytes