Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e49d69696c97994…

MALICIOUS

PDF

77.0 KB Created: 2021-03-31 01:57:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-10
MD5: 6693691688dc357039e93b522eb10012 SHA-1: e4587579ef0392cdcc025f14deb51171c9e5462d SHA-256: 1e49d69696c979943259fcddaa049d6d09d45d3302c2b19f0c032318c557da07
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, which is likely intended to trick the user into downloading a malicious file by appearing to be a free download link for a book. No scripts were extracted, but the presence of the malicious URL and the detection signatures strongly indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=i+too+had+a+love+story+pdf+free+download+in+telugu PDF link annotation
    • http://waferaboteb.mypressonline.com/java_interview_questions_and_answers_for_freshers_free_download.pdfIn PDF document text
    • http://select-get.top/551478075556iex9.pdfIn PDF document text
    • http://xepezugabiposa.22web.org/how_to_deflate_eurohike_airbed.pdfIn PDF document text
    • https://cdn.sqhk.co/zopimoforaja/biahgig/puroxavu.pdfIn PDF document text
    • http://dajobod.getenjoyment.net/bulobimepofopalogukesi.pdfIn PDF document text
    • https://cdn.sqhk.co/mugegiduveb/d9J5jg7/satelotuko.pdfIn PDF document text
    • http://fojukivijivik.medianewsonline.com/side_effects_of_eating_broiler_chicken.pdfIn PDF document text
    • http://vepapin.iblogger.org/motixefute.pdfIn PDF document text
    • http://winsbig.space/98336970182r4yxo.pdfIn PDF document text
    • http://gerobotukonu.iblogger.org/reckless_love_of_god_ukulele_chords.pdfIn PDF document text
    • http://toworugesolur.getenjoyment.net/pm_awas_yojana_form_download.pdfIn PDF document text
    • http://reflectionss.space/uc_neopets_guidetycuv.pdfIn PDF document text
    • http://golden-charm.ru/what_does_intellisense_on_a_blood_pressure_monitor_meanivl8c.pdfIn PDF document text
    • http://trysoda.club/32424462034nf52l.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://zarufutebere.epizy.com/band_music_library_digital.pdfIn PDF document text
    • https://s3.amazonaws.com/pogolo/what_lean_cuisine_meals_are_gluten_free.pdfIn PDF document text
    • http://nuzinigezabab.rf.gd/aerospike_engine_design.pdfIn PDF document text
    • https://s3.amazonaws.com/kavifunaruvi/buwogajigojetofijixug.pdfIn PDF document text
    • https://s3.amazonaws.com/voxazedisula/zamozojejulorejiba.pdfIn PDF document text
    • http://reladefuxuna.onlinewebshop.net/edit_and_merge_files_online_free.pdfIn PDF document text
    • https://s3.amazonaws.com/dobikasukavu/90185232442.pdfIn PDF document text
    • http://bopamebedozupux.epizy.com/gangster_games_free_for_computer.pdfIn PDF document text
    • https://s3.amazonaws.com/gaxuremewuger/sheet_music_piano_beethoven_moonlight_sonata.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee4d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE4D 5496 bytes
SHA-256: 6c5991d494cf4a6b44609df0dc05a3f4620d00050e451367ce9b65187f8be268
font_01_sfnt_off0001011b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1011B 10208 bytes
SHA-256: 8b38862c0b3d60d3c90e010477ba2bbb190614a3227041ff1186a12362e9bc8b