Malicious PDF — malware analysis report

Static analysis result for SHA-256 19c2a272e1ed949c…

MALICIOUS

PDF

82.6 KB Created: 2021-04-01 00:15:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0945b3e8027392b8199632228df50e95 SHA-1: 97a5b9b008f179252373c4408717baf608ef745f SHA-256: 19c2a272e1ed949c4b5cff578ecbec3612d9ce8c0ca754d443869a94c5758860
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with heuristics indicating the presence of external URIs and embedded URLs. The document body, though heavily obfuscated, suggests a lure related to a 'chicken farming business plan'. The embedded URLs likely serve to redirect the user to malicious content or phishing pages, consistent with a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=chicken+farming+business+plan+sample+pdf
    • https://cdn.sqhk.co/balaragu/iUrctFA/19651031143.pdf
    • https://static.s123-cdn-static.com/uploads/4496146/normal_5ff5bdef0ae07.pdf
    • https://cdn.sqhk.co/neliwuwo/jaPha7u/road_riot_for_tango_mod_apk_unlimited_crystals.pdf
    • https://cdn.sqhk.co/bisidilit/jaOghgI/69148981044.pdf
    • http://pivolirarorip.mypressonline.com/39329756929.pdf
    • https://cdn.sqhk.co/logubaxe/bgjhVjj/girl_next_door_saving_jane.pdf
    • https://cdn.sqhk.co/dodalowogiv/dheRotp/41620414238.pdf
    • http://difipalilif.scienceontheweb.net/alberta_highway_map.pdf
    • https://static.s123-cdn-static.com/uploads/4368770/normal_5fe10756ad9a8.pdf
    • https://static.s123-cdn-static.com/uploads/4468286/normal_5fc9853870acc.pdf
    • https://cdn-cms.f-static.net/uploads/4422627/normal_6032cf4a6b882.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4e6d9e99-38b9-4340-a80e-fef7b76d6d75/7186618410.pdf
    • http://kufekisawisewo.onlinewebshop.net/anemia_hemolitica_autoinmune_en_pediatria.pdf
    • http://katakamubu.rf.gd/shipboard_automatic_identification_system_displays.pdf
    • http://posesesu.epizy.com/68580765223.pdf
    • https://uploads.strikinglycdn.com/files/3e6e933a-feeb-4cff-a97d-5f6555261efe/how_to_tell_if_your_solar_inverter_is_working.pdf
    • https://uploads.strikinglycdn.com/files/7c655ce2-4186-4281-b46d-756573ab84cb/42555554816.pdf
    • http://kilarosine.atwebpages.com/treatment_of_anxiety_and_depression.pdf
    • https://uploads.strikinglycdn.com/files/24b1a1a9-e741-45b9-a5be-9ddcade464a1/49180550893.pdf
    • http://nesuvumuvugelo.epizy.com/mimirebodomusob.pdf
    • https://uploads.strikinglycdn.com/files/8454d6e8-be91-4945-ba9c-4da70704a829/3841177190.pdf
    • https://uploads.strikinglycdn.com/files/e33efbaa-23b3-4f9d-b440-0fd09837d918/55037033945.pdf
    • https://uploads.strikinglycdn.com/files/c5825fcc-762f-4c00-820e-9127c1301673/woferos.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000105bc.bin
582505bb0e530bd1d46707dcb2c1058aa091b1046d2e92cf526202b27ecf0fb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x105BC 5680 bytes
font_01_sfnt_off000118d6.bin
8ea1bd451960c6f5f9a944546ed938cb71386ddcc20729fc123e29c504f04feb
pdf-font-stream PDF embedded font (sfnt) at offset 0x118D6 10540 bytes