Malicious PDF — malware analysis report

Static analysis result for SHA-256 1d1e594051568220…

MALICIOUS

PDF

82.2 KB Created: 2021-03-23 06:16:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8271132587150091b68bd0175f6abd30 SHA-1: ab1566274e6a32bbf510dd97588bb50325dff4d4 SHA-256: 1d1e5940515682201df5d72c976a29d0f33f3d07b4456fa9c9c8ce295e06b570
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that directs users to a phishing site, as indicated by the 'ML_NYX_PDF_MALICIOUS' heuristic and ClamAV detection. The document body, though heavily obfuscated, suggests a lure related to 'sound relationship house explained'. The presence of an external URI points towards a phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/aws?utm_term=sound+relationship+house+explained
    • https://static.s123-cdn-static.com/uploads/4366405/normal_5fff8064cde03.pdf
    • https://static.s123-cdn-static.com/uploads/4490138/normal_5ff529a7d54ba.pdf
    • http://puxefesezosowej.22web.org/the_time_travelers_wife_full_movie_in_hindi_free_download.pdf
    • http://workbykoder.xyz/lagu_opening_chuunibyou_season_14jlxk.pdf
    • https://static.s123-cdn-static.com/uploads/4479226/normal_5fdd9d6dba71e.pdf
    • https://cdn-cms.f-static.net/uploads/4494451/normal_5fd876704c744.pdf
    • http://tryraisins.pro/cadastral_information_updatingy5dvi.pdf
    • http://pojokup.getenjoyment.net/let_s_learn_english_7th_year_basic_education_student_s_book.pdf
    • https://cdn-cms.f-static.net/uploads/4501198/normal_6056886d9eab1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f9c07af6-95e2-4680-a960-2afc6896fa4c/sony_bdv-e3100_instruction_manual.pdf
    • https://s3.amazonaws.com/tokit/gerhard_de_beer_scouting_report.pdf
    • http://lugivodunoxasi.atwebpages.com/solving_quadratic_equations_examples.pdf
    • https://s3.amazonaws.com/divelatoxa/tor_browser_android_reddit.pdf
    • https://uploads.strikinglycdn.com/files/87bb0bdb-445b-499c-bf2d-0ff2522f865b/95047058892.pdf
    • https://s3.amazonaws.com/ragejufa/86745349464.pdf
    • https://s3.amazonaws.com/silubebebefuju/storm_front_jim_butcher.pdf
    • https://uploads.strikinglycdn.com/files/6072d197-8b8b-4f1e-b2a4-ba7d660e86af/12672220373.pdf
    • https://uploads.strikinglycdn.com/files/5efbbaee-0f7d-4453-a7ec-46f7639e843b/what_are_the_differences_between_veins_and_arteries.pdf
    • http://logiweliziweje.onlinewebshop.net/gogetabedulazakozugik.pdf
    • http://dusexodabedokak.rf.gd/gowedopiwak.pdf
    • https://uploads.strikinglycdn.com/files/d6e27a2b-2a2f-42f0-9972-1419bd8c0efe/65826892067.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103ff.bin
5188b4f7b29df3b55ba4854a37189b95891bbc46ea8a9d48f7d77d0ac56a8033
pdf-font-stream PDF embedded font (sfnt) at offset 0x103FF 5220 bytes
font_01_sfnt_off000115b6.bin
bdf57a068896b00644dfc0c9335bda75f796ef57a6cf2f03be585f0ea97cd515
pdf-font-stream PDF embedded font (sfnt) at offset 0x115B6 10604 bytes