Malicious PDF — malware analysis report

Static analysis result for SHA-256 14b92157b049c387…

MALICIOUS

PDF

73.7 KB Created: 2021-03-30 06:06:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 75164281c1481e1b07420b218059448b SHA-1: 7add789866d60417f52d1d40e0ed074588bbbf68 SHA-256: 14b92157b049c3872dad08e0a3db5865dbc32f43b506de1fdb9a96978708d97c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, appears to be a lure related to ticket vendor comparisons, aiming to trick users into visiting the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=seatgeek+vs+ticketmaster+reddit
    • http://prequester.online/ditenat92538.pdf
    • http://scriptbook.xyz/gomalujidazepuluwitbwbti.pdf
    • https://cdn.sqhk.co/jivonaxadu/dAZhfex/dark_souls_boss_meme_compilation_v2.pdf
    • https://cdn.sqhk.co/nepusoliweda/jjjPZie/3698796992.pdf
    • https://cdn.sqhk.co/nobukomorur/mwvgcib/deribagovilexofaja.pdf
    • https://cdn.sqhk.co/winogolelog/ibihugc/34470690371.pdf
    • https://cdn.sqhk.co/dijabidasu/QlgeVgg/zigolajimedawesifivumit.pdf
    • https://cdn.sqhk.co/kefesizo/biigiWU/how_to_make_origami_pro_apk.pdf
    • https://cdn.sqhk.co/bizujutenifo/afVcfgi/dhoom_2_hrithik_roshan_bike_name.pdf
    • http://semengergel.ru/clinical_data_management_software_free_downloadshpgy.pdf
    • http://sparzha.club/hand_sewing_basicsv71xk.pdf
    • http://presentinsta.site/halloween_fake_nails_amazon2mstv.pdf
    • https://cdn.sqhk.co/mozigizax/jdjajjk/restless_heart_syndrome_piano_sheet_music_free.pdf
    • https://cdn.sqhk.co/mugolino/V7phihf/life_is_strange_3_max_and_chloe.pdf
    • https://cdn.sqhk.co/vigibizez/IHNaghZ/rush_hour_3_netflix_uk.pdf
    • http://ch-redirect.icu/14954549022219vi.pdf
    • http://paganel.world/counter_strike_2_game_for_pcbgm4p.pdf
    • http://genusadnlo.space/14660874976ho695.pdf
    • https://cdn.sqhk.co/fedelubu/Vjw1ets/87831196707.pdf
    • https://cdn.sqhk.co/bigulikexupa/gd9Dhgf/tourist_bus_simulator_pc_free_download.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fizufapu/summary_of_romeo_and_juliet_act_1_prologue.pdf
    • https://s3.amazonaws.com/pajukovuxetu/69124983551.pdf
    • https://s3.amazonaws.com/zulezov/37875802844.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3ec.bin
749c2b95fb60ab9bebc61b2585b1dd501e6bee7cbb49df4d860fd0861fe96ef6
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3EC 5452 bytes
font_01_sfnt_off0000f66d.bin
3f3df928e1d06d120ce3bb316dac0a9043ac670ad1349de8cbc9c106822fab6a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF66D 10216 bytes