Malicious PDF — malware analysis report

Static analysis result for SHA-256 10fec5e929881597…

MALICIOUS

PDF

78.5 KB Created: 2021-03-14 11:45:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ab14bdd25df435eb46788df4bc83d1a2 SHA-1: bfdca42bdf68a5ea70179c535595a63abf1b961a SHA-256: 10fec5e929881597a460b95e5033870b3124be21792bda5c82e72d219d7cc236
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains multiple suspicious URLs, one of which is presented as an invisible link and leads to a PDF download. The document body, though heavily obfuscated, contains references to 'Dumb ways to die 2 apkhere', suggesting a lure to trick users into downloading the malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LURE
    PDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/wix?keyword=dumb+ways+to+die+2+apkhere
    • https://cdn-cms.f-static.net/uploads/4469106/normal_602db2c0719ec.pdf
    • https://cdn-cms.f-static.net/uploads/4495059/normal_600e30815d183.pdf
    • https://cdn-cms.f-static.net/uploads/4403818/normal_5fdc2db18234c.pdf
    • http://hydraruzxpnew4af.exchange/quais_os_tipos_de_sistema_operacionais_existentesvn04z.pdf
    • http://dorightschool.com/lexewitwm9gg.pdf
    • http://edaruzal.xyz/59969909315zfns9.pdf
    • http://thesalle.xyz/6325875007nfg7t.pdf
    • http://alternativeinfluencenetwork.net/22450559591rknmv.pdf
    • http://ionatr.fun/lost_stars_main_characterse183m.pdf
    • http://securitycheckingbrowservkcom.xyz/monster_hunter_illustrations_2_hardcoverfhpoz.pdf
    • https://cdn.sqhk.co/jebuxanit/uwidjej/sheet_music_for_jeopardy_theme_song.pdf
    • https://cdn.sqhk.co/sipobufiw/jria5r7/kolujerawesuxedikewirir.pdf
    • http://stikc.xyz/pronunciation_past_simple_regular_verbs1x6qv.pdf
    • https://cdn.sqhk.co/duvapegoleva/h3xgfjW/gevasuwoxezamovipegew.pdf
    • http://helplnstagramcontact6088758.com/tower_defense_simulator_roblox_live_eventhg9e2.pdf
    • http://glasshookahcatering.com/the_appraisal_of_real_estate_12th_edition_free_downloadpt1e2.pdf
    • http://sportplays.ru/17660458546mpndk.pdf
    • http://ionatr.space/two_dots_game_rules7w83b.pdf
    • https://cdn.sqhk.co/weteroliwo/RDJvnRG/run_run_as_fast_as_you_can_shrek.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://34ea5197-a9e9-4ba5-99bb-a7dd7aeba98b.filesusr.com/ugd/234f58_899296f27bd74ee89a6453d25ed38af3.pdf?index=true
    • https://70010cfe-69b1-4fe9-a336-bdfe2418dc1e.filesusr.com/ugd/f1d680_0f529a96e45445e282641c1c4215668c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f453.bin
3fb3bd2a9549811c9ea3a4674f7c9d88097fe1310c2710166303bda909e33daa
pdf-font-stream PDF embedded font (sfnt) at offset 0xF453 5696 bytes
font_01_sfnt_off000107a0.bin
6c9e386e5dca31d9f2db37df8e51146b04c8f38667f4d7f2ab0c4e7c10548378
pdf-font-stream PDF embedded font (sfnt) at offset 0x107A0 10880 bytes