Malicious PDF — malware analysis report

Static analysis result for SHA-256 16eb202aba5ce547…

MALICIOUS

PDF

94.3 KB Created: 2021-04-06 15:07:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 26d2c7109415e4ab7d4641afaae68602 SHA-1: 50e67afe67cd4db963fe2c66db3d0f1cfcf7d04a SHA-256: 16eb202aba5ce54751e378cb9c9621ac1bba3ec00d643b43360331a0dd1bd5a8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of an external URI pointing to a URL containing 'stubhub tickets legit reddit' suggests a phishing lure related to ticket sales. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to trick users into visiting a compromised site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=stubhub+tickets+legit+reddit
    • http://jitudowifite.iblogger.org/39079778595.pdf
    • https://cdn.sqhk.co/zijikunu/olLtha8/remix_to_ignition_r_kelly_mp3_download.pdf
    • https://cdn.sqhk.co/virurewev/bvhjnFi/best_rock_n_roll_drum_solos.pdf
    • http://napozilukuse.22web.org/nuxobelelo.pdf
    • https://cdn.sqhk.co/bowevuva/ujhcHTB/traffic_racer_apk_download_old_version.pdf
    • https://cdn.sqhk.co/gabamulijawe/ia1CGjj/basketball_fans_worldwide.pdf
    • http://rasazevedip.22web.org/70730299396.pdf
    • https://cdn.sqhk.co/letijefa/WZqjaii/xr2206_function_generator_kit_circuit_diagram.pdf
    • https://cdn.sqhk.co/libavesonon/ghhjfih/npr_one_vs_npr_news.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://sivopob.epizy.com/88856889481.pdf
    • https://s3.amazonaws.com/divexikav/ganowezuboro.pdf
    • http://rutenodisekorin.rf.gd/travel_itinerary_planner_template_excel.pdf
    • https://uploads.strikinglycdn.com/files/114ae334-ff7c-43ab-9f80-74494e703143/10979323620.pdf
    • https://uploads.strikinglycdn.com/files/4287b1a9-4133-42a9-9baf-939a75e817c3/pumuratozutesexewokorir.pdf
    • https://uploads.strikinglycdn.com/files/ddccc55d-0d9f-4c04-bdc3-1f319d81c295/datikejexanabironoki.pdf
    • https://uploads.strikinglycdn.com/files/11e78d37-09d2-4965-8e82-93a9218b8588/77362926546.pdf
    • https://uploads.strikinglycdn.com/files/927f098f-77a9-4c0f-81d3-a2638296bc87/tin_tin_chinese_food_menu.pdf
    • https://s3.amazonaws.com/remeranexe/sketchup_pro_2018_trial_user.pdf
    • http://vazorilumi.epizy.com/american_pie_all_parts_allofpc._in.pdf
    • https://s3.amazonaws.com/mogedozara/what_does_the_lottery_symbolize_for_rose.pdf
    • https://s3.amazonaws.com/zesixefe/post_nuptial_agreement_template_north_carolina.pdf
    • http://defisatum.epizy.com/how_to_find_maximum_speed_in_calculus.pdf
    • https://s3.amazonaws.com/mekonulegipero/grief_syndrome_1._10.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001325c.bin
49cdaaed498728acf8c77783608da39fd8460378a27f8acdb659d01cd13fa2f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1325C 5296 bytes
font_01_sfnt_off00014455.bin
64d3be7523dc25d7308ccde535cf328bb8497028b71c349b00f0f7bb19e16e23
pdf-font-stream PDF embedded font (sfnt) at offset 0x14455 11604 bytes