Malicious PDF — malware analysis report

Static analysis result for SHA-256 10954f1b679e51d9…

MALICIOUS

PDF

81.2 KB Created: 2021-04-02 13:54:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 816305b6443322b698c5a677dda98807 SHA-1: 957f5b4dba4613043ed92a76e373838c7f4331f2 SHA-256: 10954f1b679e51d9e2dd6e50cbcd6d49dae45117c39b6638911911f0b01024e7
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF document uses a cloud document lure to trick users into clicking an embedded link. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded URL points to a suspicious domain, likely serving as a phishing or malware distribution point.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=software+project+management+skills
    • http://zomewegi.iblogger.org/cursive_handwriting_worksheets_numbers.pdf
    • http://pixujuxe.mypressonline.com/pillars_of_eternity_2_poradnik.pdf
    • http://peromopativej.mypressonline.com/how_much_does_a_3.5_ton_trane_ac_unit_cost.pdf
    • http://zezasasipow.iblogger.org/49305194655.pdf
    • http://melowimaz.getenjoyment.net/rivazosifakamarikowa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/zurovajij/homelite_chainsaw_operation.pdf
    • https://s3.amazonaws.com/kakef/my_apple_id_security_answers.pdf
    • https://uploads.strikinglycdn.com/files/d4cad469-0635-4baa-bf9e-c90d255258be/2000_skyline_aljo_travel_trailer.pdf
    • https://s3.amazonaws.com/tuxutedi/10419777953.pdf
    • https://uploads.strikinglycdn.com/files/73846972-726e-4b42-b188-ae06d4731790/99176162517.pdf
    • http://dosibaguluf.epizy.com/willingness_to_pay.pdf
    • https://uploads.strikinglycdn.com/files/c30d7d90-ecdf-42c6-8b72-9be9855e2076/26445961227.pdf
    • http://nebamolowitumik.epizy.com/search_form_sql_injection.pdf
    • http://toxukofotu.rf.gd/nelevosin.pdf
    • https://67dc9804-4028-4298-afd7-d431d2c16fe6.filesusr.com/ugd/559c84_da4e0703e16d457fab5c21905f514ff2.pdf?index=true
    • http://muvaxuzuf.rf.gd/asc_842_fasb.pdf
    • https://e108c0fa-8e70-4110-aab7-e0d30777705f.filesusr.com/ugd/d9966b_0b8a82c7240f486aa9d84c32c6fe33c9.pdf?index=true
    • http://xewenofos.epizy.com/55813453134.pdf
    • https://7133fc40-0b9c-4701-b953-e7fafc934b44.filesusr.com/ugd/70a38d_47353c88d93a4f7f8ceb55dd7804fcf6.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ffb4.bin
dbb593a68692b24ec8a1b64b7105a80a48c84ddacf807aaef08ceafe51905c37
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFB4 5672 bytes
font_01_sfnt_off0001130a.bin
75062fa97b0dc1f5d631102f0e44d9e5eeb734902a7c4b45fad56034d428f015
pdf-font-stream PDF embedded font (sfnt) at offset 0x1130A 10620 bytes