Malicious PDF — malware analysis report

Static analysis result for SHA-256 2148e1f7e1982b39…

MALICIOUS

PDF

84.3 KB Created: 2021-05-18 15:53:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 04ea1ea02fdd76062f5b0fb85323cf5f SHA-1: 1ade903ad71e081dead30d40e3ea79b047c30a4e SHA-256: 2148e1f7e1982b3967483f1b3e8ab6bca35c51d07b6ce415c36b31b40d1a7ed0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier, indicating malicious intent. The embedded URL points to a suspicious domain associated with game hacks, suggesting a phishing or social engineering lure. No scripts were extracted, but the PDF structure itself contains the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=coc+trip+game+clash+of+clans+hack+download+2019
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/180bbe10-f7e6-4dbf-ae55-b39e9832ab2c/how_to_connect_dvd_vcr_combo_to_tv_with_cable_box.pdf
    • https://s3.amazonaws.com/genedesowul/junudokogufu.pdf
    • https://s3.amazonaws.com/lixisariwulo/gastroc_equinus_deformity_icd_10.pdf
    • https://uploads.strikinglycdn.com/files/e8f9d988-dea0-4022-b614-0455c81ad724/11331671691.pdf
    • https://s3.amazonaws.com/bewibiwat/vodazosopi.pdf
    • https://s3.amazonaws.com/xisakazelelinim/levolofimuzusodegim.pdf
    • http://nigukeja.epizy.com/pokemon_insurgence_location_guide.pdf
    • https://s3.amazonaws.com/potamotaz/what_is_the_study_of_population_called.pdf
    • https://uploads.strikinglycdn.com/files/26a7020d-c7c5-472f-b853-9f7b249da11c/98283972805.pdf
    • https://uploads.strikinglycdn.com/files/b87708f7-49cd-4766-aa72-84ec73105d30/apple_ipod_nano_1st_generation_battery.pdf
    • https://uploads.strikinglycdn.com/files/9505730b-9da1-4992-ab72-36c7a5f5ee41/52821761760.pdf
    • https://s3.amazonaws.com/jipowumat/cloudy_with_achance_of_meatballs_picture_book.pdf
    • https://uploads.strikinglycdn.com/files/30045208-af47-49b2-ba09-677dce8e7220/97731704991.pdf
    • https://uploads.strikinglycdn.com/files/0e83f311-30e3-46be-9266-d8a64568ceae/phrasal_verbs_dictionary_online_longman.pdf
    • https://s3.amazonaws.com/fumiposamisur/wagumaruwidepakipebuvobow.pdf
    • https://s3.amazonaws.com/nezanurugega/8524848470.pdf
    • https://uploads.strikinglycdn.com/files/46ff567e-d5ee-4e2d-be0f-0dcbf4a38611/27192951490.pdf
    • https://uploads.strikinglycdn.com/files/4bc2c69f-92c2-4120-8ae1-6c936385cf83/weber_bbq_recipes_fish.pdf
    • https://uploads.strikinglycdn.com/files/93968f7c-4880-474e-be8a-b751a27e18dd/orbital_diagrams_for_all_elements.pdf
    • https://s3.amazonaws.com/bipepezuwed/27585602723.pdf
    • https://s3.amazonaws.com/lepefi/kebeledij.pdf
    • https://uploads.strikinglycdn.com/files/08c97b09-31f2-4f82-ab5d-11dfd82f4153/guwojolugopusatin.pdf
    • http://vubixegigag.rf.gd/vamugelutomi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec32.bin
b0bf3d9e8fd98222ee7babd74b5fd8485b623c0fddfa7a60f04fd81608e1ab66
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC32 6112 bytes
font_01_sfnt_off000100e0.bin
05293a0f052a253f3921142eaaf8c38f5ad576b2020dfc96d8d6179fd017d921
pdf-font-stream PDF embedded font (sfnt) at offset 0x100E0 1644 bytes
font_02_sfnt_off0001093e.bin
ee196e68bb69d0f7f11a87a0eba6e5778dc9521423bd14987a6032629668d725
pdf-font-stream PDF embedded font (sfnt) at offset 0x1093E 10668 bytes
font_03_sfnt_off00012e06.bin
354dce64f07f3d7acdf6a04edf763950ffbfec4edcbb4bfe17b65a83544077bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E06 16036 bytes