Malicious PDF — malware analysis report

Static analysis result for SHA-256 21d9deda283be97b…

MALICIOUS

PDF

78.7 KB Created: 2021-02-20 04:41:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-17
MD5: 4991428144a041797d3d1fa5e82457d4 SHA-1: df622506fc0f92536c440e02cc2ea2bb54b655c4 SHA-256: 21d9deda283be97bc031e1aacdec100a1f3d3c75ea2fde9c5f0efda53a7e9acc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier. It contains an embedded URL pointing to 'bologen.ru' which is presented as a hack for 'Zynga Spades Plus'. This strongly suggests a phishing or malware distribution lure. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic indicate the document's primary function is to redirect the user to a malicious external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=zynga+spades+plus+hack PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4386837/normal_600b8eb873011.pdfIn PDF document text
    • https://cdn.sqhk.co/rabataxuvax/iBogeig/tolifo.pdfIn PDF document text
    • https://cdn.sqhk.co/lojosewude/iitEjhb/nefamevavukanixid.pdfIn PDF document text
    • https://cdn.sqhk.co/vinasujitupe/jjhicia/suwupitezagu.pdfIn PDF document text
    • http://naturaitalia.space/turn_off_adaptive_icons_androidbe8nq.pdfIn PDF document text
    • https://cdn.sqhk.co/fofesali/Zgahfcb/pitoj.pdfIn PDF document text
    • https://cdn.sqhk.co/norifasil/dgchcj5/red_ball_4_stage_54.pdfIn PDF document text
    • https://cdn.sqhk.co/jojikoxazew/gdhjjid/radiant_defense_foundation_reviews.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4404755/normal_5ff272ca3714b.pdfIn PDF document text
    • https://cdn.sqhk.co/pulobegefuzi/XJjhRij/pigewaxewugujulak.pdfIn PDF document text
    • http://prizinsta.site/dajusalelatjdc4.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/rujabepifar/38887237056.pdfIn PDF document text
    • https://s3.amazonaws.com/dazuxujepov/phonics_hero_android.pdfIn PDF document text
    • https://s3.amazonaws.com/nijosinizo/graphing_trig_functions_practice_worksheet_with_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/kabisebax/conjuntivitis_bacteriana_en_perros.pdfIn PDF document text
    • https://s3.amazonaws.com/padosumifubobo/ninewotodirevibefog.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f838.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF838 5364 bytes
SHA-256: f7bf6e2bb503d5dc91a84f57a8fe5e7c3849b2cb8681e5ad434da2af509aefe9
font_01_sfnt_off00010a86.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A86 10344 bytes
SHA-256: 421d08ac46f619a27268194280e92b7a05abe18adad6a4db5e5d61d280c7ddf2