Malicious PDF — malware analysis report

Static analysis result for SHA-256 1bf49cb39760a0d9…

MALICIOUS

PDF

80.5 KB Created: 2021-03-14 18:28:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0d92f65cea67db5c6a4f68592875bfd8 SHA-1: 26e59114a9fcc04209680528865253c62685b26a SHA-256: 1bf49cb39760a0d9e575ead05a7f6ed59bf7428e86091e78d536432b6d662e2b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a phishing or malware download site. The document body, though heavily obfuscated, contains text related to a movie title, suggesting a lure to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=el+amor+en+tiempos+de+colera+pelicula+en+espa%25C3%25B1ol
    • http://figimumagoko.mygamesonline.org/gipukufevidudosajav.pdf
    • http://sibasijiv.22web.org/inspire_science_grade_4_worksheets.pdf
    • http://suporefebakibur.mygamesonline.org/what_are_the_components_of_a_news_story.pdf
    • http://nuzimodulinuke.iblogger.org/lusisavujuluzurorobegerek.pdf
    • https://cdn.sqhk.co/zifeduwa/inGigje/rounded_bullnose_corner_trim.pdf
    • https://nuresoxak.weebly.com/uploads/1/3/1/3/131380504/lowijar.pdf
    • https://togazozaxezux.weebly.com/uploads/1/3/1/6/131606461/ac8740517c5d43.pdf
    • http://pawelemofub.iblogger.org/criminal_background_check_form.pdf
    • https://cdn.sqhk.co/xiladuxe/vwqihgi/cultist_tft_set_4_comp.pdf
    • http://roboludawu.mywebcommunity.org/what_is_the_rarest_hair_color_with_green_eyes.pdf
    • https://cdn.sqhk.co/zexoribuj/djh9A0F/dark_humor_riddles_with_answers.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://c140f178-ee45-427e-91fe-a3c5f821f67e.filesusr.com/ugd/ebc5f9_fc1a2345ae5f4228a4589dc0a5a384bb.pdf?index=true
    • https://uploads.strikinglycdn.com/files/7258adf6-7e8e-4a6b-b59b-45828850b545/how_to_use_turtle_beach_600_on_pc.pdf
    • http://zubiluwetij.myartsonline.com/munoxatuvoxotu.pdf
    • https://uploads.strikinglycdn.com/files/ad323e01-b90d-41f7-8427-5a4a905a6d76/what_is_considered_a_commercial_vehicle_in_the_state_of_florida.pdf
    • https://uploads.strikinglycdn.com/files/5e869527-b6d6-4d0b-a9ef-248398526de5/3698910522.pdf
    • http://liraperuwuw.atwebpages.com/presentation_materials_effective_c_in_an_embedded_environment.pdf
    • http://xedunago.rf.gd/kosame.pdf
    • https://uploads.strikinglycdn.com/files/ec34a5eb-d47b-43bd-8d45-d6d266e3c55a/blade_inductrix_fpv_plus_manual.pdf
    • https://d23eb412-52e1-45ef-a32a-0c032022daee.filesusr.com/ugd/03485a_4a25a8e4de754e07b016b982b3e11cf5.pdf?index=true
    • https://7a512b58-7189-4bc4-8343-f643fa9054c9.filesusr.com/ugd/1e52da_687183cf53e740bb86a605e332a22621.pdf?index=true
    • https://238a82c5-85a8-4641-a991-2f0f5270ddc4.filesusr.com/ugd/63f22d_d8614eed86164d4f8f86015c458f0c3b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/522e5ddb-4c9d-40b1-ba73-d55104ea7329/45763663213.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea30.bin
861ba69eef7d5e34730ba4d9034beeedfb98319ee686a7d3219a650e0ef33d08
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA30 3700 bytes
font_01_sfnt_off0000f771.bin
6d93fc0267e40f5f9ee1581d469f9fbe84c853510d36ee77692822edcf78d74c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF771 5388 bytes
font_02_sfnt_off0001096a.bin
417c5e5a4660080322d26d91c65cf86b6867e75d72ad9b2bca2dadb72fafff63
pdf-font-stream PDF embedded font (sfnt) at offset 0x1096A 13168 bytes