Malicious PDF — malware analysis report

Static analysis result for SHA-256 1833b13acec778c6…

MALICIOUS

PDF

77.7 KB Created: 2021-04-07 08:53:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e0c75ff183af07a8c7d788f97652df03 SHA-1: d0e6a93210e55a3b6774ba57c5a98897aa672a64 SHA-256: 1833b13acec778c641a744cf127180a291d1d5e4c4726b2ad75fbcc5103acc4b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'https://xezojetit.ru/strik?utm_term=openfiler+default+user+password', which is highly suspicious and likely leads to a malicious site or download. No scripts were extracted, but the presence of the malicious URI strongly suggests a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=openfiler+default+user+password
    • http://xizapataruxeku.mygamesonline.org/ketoba.pdf
    • https://cdn-cms.f-static.net/uploads/4464861/normal_600dc32ea14c3.pdf
    • https://static.s123-cdn-static.com/uploads/4416151/normal_5ff306a9517cf.pdf
    • http://midunetojonawiw.mywebcommunity.org/where_to_buy_bayer_contour_next_test_strips.pdf
    • https://cdn-cms.f-static.net/uploads/4477921/normal_60407952f3135.pdf
    • https://cdn-cms.f-static.net/uploads/4404975/normal_603d00d1abecb.pdf
    • http://betizekaxu.getenjoyment.net/gajukidobazarela.pdf
    • https://static.s123-cdn-static.com/uploads/4481154/normal_600208b8ee600.pdf
    • https://static.s123-cdn-static.com/uploads/4369653/normal_5ff681b2eae9d.pdf
    • http://jolijivik.scienceontheweb.net/navy_seal_how_to_fall_asleep.pdf
    • https://cdn-cms.f-static.net/uploads/4479237/normal_601da96d244c1.pdf
    • http://ladiluvame.mypressonline.com/atomic_habits_epub.pdf
    • https://cdn-cms.f-static.net/uploads/4380080/normal_60190ac216204.pdf
    • http://jadaribod.mygamesonline.org/harvard_business_review_must_reads_on_strategy.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wujafivabipo/nujijejigavemupo.pdf
    • http://mozutulobiris.onlinewebshop.net/alpha_phonics_vs_all_about_reading.pdf
    • https://s3.amazonaws.com/wazotojemov/zudamagubikosorawilaz.pdf
    • https://s3.amazonaws.com/pazerogasarinu/forex_pin_bar_strategy.pdf
    • https://uploads.strikinglycdn.com/files/ade2de82-9a0c-444e-9681-904ac45b511b/foxoxos.pdf
    • https://uploads.strikinglycdn.com/files/66525b34-a9d8-4938-a117-2543be38ca2a/82453073670.pdf
    • https://uploads.strikinglycdn.com/files/970a636c-6291-4114-a387-acb9dca79f7f/how_to_overcome_anxiety_when_public_speaking.pdf
    • http://telosizaba.onlinewebshop.net/automotive_car_parts.pdf
    • https://uploads.strikinglycdn.com/files/3c7da480-1423-44e6-a10e-4cfd31e33af4/what_is_a_general_release_of_all_claims.pdf
    • https://s3.amazonaws.com/xapota/fenudixejerilegezikupugiz.pdf
    • https://s3.amazonaws.com/wudibirewuduto/54525322645.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0f4.bin
1f50f30932b92c4cd8898adeeb54e2c534dfd0b1ec51caac6a3dfc4f61e3f382
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0F4 5156 bytes
font_01_sfnt_off00010296.bin
a157c206f6899254d8a1cb1714e693165c5742de2eaee805818b0a162d72ecb1
pdf-font-stream PDF embedded font (sfnt) at offset 0x10296 11444 bytes