Malicious PDF — malware analysis report

Static analysis result for SHA-256 1bf7c564da7767fd…

MALICIOUS

PDF

69.3 KB Created: 2021-04-03 20:46:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4c97ae68dd6b4377e74c64d9273ef500 SHA-1: 4583cf5d5213bdde2d1b6f82f9a0ed83c9bef4ac SHA-256: 1bf7c564da7767fd5900216401d445cf4a959ca4baf54afdd271a657d0b58bd3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating the presence of external URIs. The document body, though heavily obfuscated, suggests a lure related to a 'Cisco rv130 admin guide'. The embedded URLs likely lead to the download of a second-stage payload, consistent with a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=cisco+rv130+admin+guide
    • https://cdn.sqhk.co/gafisasiwu/Fluje8o/age_of_empires_3_apk_game.pdf
    • https://cdn-cms.f-static.net/uploads/4427079/normal_604c9c13b91b9.pdf
    • https://cdn.sqhk.co/rubogomuweme/ngjkieX/gunblood_game_2_player.pdf
    • http://kismyketio.com/download_adobe_audition_3.0_free_crackaq7vd.pdf
    • https://cdn-cms.f-static.net/uploads/4374181/normal_6047afebc0e81.pdf
    • https://cdn.sqhk.co/lasokixon/PjgVGvK/school_management_software_php.pdf
    • https://cdn.sqhk.co/jesupasuzoku/Jidhcgj/setadepages.pdf
    • http://glasshookahcatering.com/khanna_paper_mills_ltd_annual_reportthbdg.pdf
    • http://contact-git.top/23526658531tk2x.pdf
    • https://cdn.sqhk.co/gidenateg/g90haXh/25257860554.pdf
    • https://cdn-cms.f-static.net/uploads/4370309/normal_5fd9083b1b3f2.pdf
    • http://orehi-siberian-force.online/82251108324xqh4a.pdf
    • https://static.s123-cdn-static.com/uploads/4485436/normal_5fdd67bf26703.pdf
    • http://tokio-2020.fun/wosomop93f81.pdf
    • https://cdn.sqhk.co/depadukat/h7zheIz/livirelatasanilodepak.pdf
    • http://bijeledi.iblogger.org/duxupolaxu.pdf
    • https://static.s123-cdn-static.com/uploads/4401697/normal_6006e1bbe4275.pdf
    • https://cdn.sqhk.co/xotosobupis/iibgehh/us_conflict_game_download.pdf
    • https://cdn.sqhk.co/vujaderaz/hbdidm2/change_my_boost_phone_number.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fisulefajow/xasarut.pdf
    • https://s3.amazonaws.com/megodipewukitoj/amoeba_sisters_photosynthesis_and_cellular_respiration_answers.pdf
    • http://relogevavikidid.epizy.com/tardis_bookcase_plans.pdf
    • https://s3.amazonaws.com/gomakobez/daily_calendar_excel_sheet.pdf
    • https://s3.amazonaws.com/kewakuko/54728235021.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d195.bin
6936adff92d79a4b12b07d8daebea141b4375920f7bd2feb241b248f4742fbc0
pdf-font-stream PDF embedded font (sfnt) at offset 0xD195 5552 bytes
font_01_sfnt_off0000e464.bin
88fb81caab264a1986aac57b9fa057920d0bcac77f1c290a759c14bcbabba0f1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE464 9980 bytes