Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d001775b4d4c60d…

MALICIOUS

PDF

189.9 KB Created: 2021-03-14 19:26:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 83b9f116507295ccfb21e31c9808d094 SHA-1: b2684b60cda1b5764aa57e79969601b6cca176af SHA-256: 1d001775b4d4c60da1509c8593d8fb5bb7caac21bdf1b407d482d8707bd7768c
144 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF containing embedded JavaScript and external URLs, flagged by ML classifiers and ClamAV as malicious. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' indicates the document likely instructs the user to open a password-protected archive, a common tactic to bypass gateway security. The embedded JavaScript likely facilitates the download and execution of a secondary payload from one of the identified URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=pic+basic+pro+manual+espa%25C3%25B1ol+pdf
    • http://modozadubop.mywebcommunity.org/73876259902.pdf
    • https://pavibizad.weebly.com/uploads/1/3/0/7/130740264/6474712.pdf
    • https://lobavasato.weebly.com/uploads/1/3/1/4/131483685/8603547.pdf
    • https://xejukosaxup.weebly.com/uploads/1/3/1/4/131437924/3170352.pdf
    • https://jugusunoju.weebly.com/uploads/1/3/4/6/134625161/2bc25b0d.pdf
    • https://wudigunufite.weebly.com/uploads/1/3/4/6/134611509/9930294.pdf
    • http://wimobilo.iblogger.org/59641215662.pdf
    • https://fusesekomufe.weebly.com/uploads/1/3/1/6/131606177/14ba77269090a.pdf
    • http://tagaporigowekis.mygamesonline.org/45719183582.pdf
    • https://jokilexagazoxo.weebly.com/uploads/1/3/4/6/134602179/2767339.pdf
    • https://fumaletaseker.weebly.com/uploads/1/3/1/3/131381433/a288910190fd4af.pdf
    • https://guvijubeb.weebly.com/uploads/1/3/5/3/135318684/2868835.pdf
    • http://fowaxulop.iblogger.org/tesiv.pdf
    • https://mizavujubamu.weebly.com/uploads/1/3/0/7/130775062/senisini.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/5eeb1ded-807b-45d7-a811-a1b2732e5ea4/how_many_players_can_play_joking_hazard.pdf
    • http://kexetuleta.epizy.com/chinese_150cc_side_by_side_for_sale.pdf
    • https://uploads.strikinglycdn.com/files/b85ad092-87bc-4678-8449-afb570c81eea/weber_grill_cooking_fish.pdf
    • https://uploads.strikinglycdn.com/files/5cd5a4c6-757e-40bc-a2a3-8181442be90a/what_verse_says_all_things_are_possible_with_god.pdf
    • http://futakanawus.onlinewebshop.net/sedimuxobofujazigaj.pdf
    • https://uploads.strikinglycdn.com/files/30464a68-4ef6-4851-9268-788878fc2955/marketing_plan_definition_kotler.pdf
    • http://luxupuxud.myartsonline.com/basic_bookkeeping_tutorial.pdf
    • https://uploads.strikinglycdn.com/files/7cfb7d15-24f5-4f0b-8392-210bd14284b2/subdivision_meaning_in_english.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00029162.bin
8dcc2a53f6122ca65fd7628ddd52e9ad9271aae879a507eee282702ebecabe1b
pdf-font-stream PDF embedded font (sfnt) at offset 0x29162 5652 bytes
font_01_sfnt_off0002a436.bin
5b83c1212116fb3518804901d134b47d385a54dc8a6410f9cd1055b2fb896d02
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A436 13940 bytes
font_02_sfnt_off0002d1db.bin
541fa2b6826b0add99b7d5a173ef1e6a5567607b5192f75b810eb17d6a563501
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D1DB 16204 bytes