Malicious PDF — malware analysis report

Static analysis result for SHA-256 100c4e820695bfda…

MALICIOUS

PDF

77.7 KB Created: 2021-07-16 09:21:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: 1884a3ab6d4d4fc8c4c1493d2f4b3ee1 SHA-1: 2a32b1a30aabbd629dc89f67f47b8054b6fc0361 SHA-256: 100c4e820695bfda6c141a9be6f55ee1469ff6f397329ea4003752a716c2af40
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged as malicious by both a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The presence of an external URI pointing to 'coretry.ru' suggests a phishing or malware distribution attempt. Although no scripts were explicitly extracted, the PDF structure and heuristics indicate it's designed to present content that directs users to this external URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/square?utm_term=how+much+is+8+quarts+of+water
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60ec83ebde8c3264fe5ef9f5/1626113003410/zabedukeriso.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e8783ec9bfd671df373de0/1625847870995/ruraminir.pdf
    • https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8d09cbf13e579204b7cf2/1625870492738/rexuwerinogev.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60ec8445b8cbe518df57d725/1626113093896/39153239507.pdf
    • https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f076d6a45c1f1e8e178f0f/1626371798408/7_kg_to_lbs.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60edbaea5982bb13d3d352f1/1626192618490/texodufubenupurusir.pdf
    • https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e8b749e6e510241f6caf62/1625864009345/what_is_the_climate_in_northern_europe.pdf
    • https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60edb33f262c1d401136c479/1626190655926/92896196951.pdf
    • https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f08d609e9f5835e2bf5b34/1626377568394/wasosikikaponi.pdf
    • https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f074c6a05bd62f13dd82df/1626371270641/jigibunuwoja.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cc8b.bin
83d09e5914d69406fec54d475781a49587f920c3aceb4aa38cb7f491ac1ff2e2
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC8B 16428 bytes
font_01_sfnt_off0000f71e.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF71E 16792 bytes
font_02_sfnt_off00010f35.bin
35f07aa1059e39e745baae65c0b80c42503f510398ad512dd06d91b37411f351
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F35 10984 bytes