Malicious PDF — malware analysis report

Static analysis result for SHA-256 22651f7c09d43ebc…

MALICIOUS

PDF

83.7 KB Created: 2021-03-21 00:43:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2c8919e7dc4215881a6066fd3d92e837 SHA-1: 808d4406b4d58e553aa72ddc0f660fe7800741c7 SHA-256: 22651f7c09d43ebc7ce741860e5690b19f39886ff536d26d406bc1611be8b911
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'dafemum.ru', which is likely intended to redirect the user to a malicious site. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, and the presence of embedded URIs indicates an attempt to direct the user to external content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/aws?utm_term=can+i+use+a+fragrance+oil+in+a+diffuser
    • http://keepsufi.space/danby_premiere_dehumidifier_user_manuald7ng9.pdf
    • http://tevoriveterusof.22web.org/60153873166.pdf
    • http://biolinkus.me/tukepomufosenupiv93wga.pdf
    • http://4escam-bot.online/dermacombin_cream_taro1ktm0.pdf
    • http://stepka2016.xyz/warcraft_arthas_rise_of_the_lich_king1uy8g.pdf
    • https://cdn.sqhk.co/vulovosovem/jdqj3QP/never_have_i_ever_extreme_questions_18.pdf
    • http://1fps.ru/revifurezejar1ib.pdf
    • http://usejus.pro/box_and_whisker_plot_worksheets_with_answers8nyty.pdf
    • http://shoppermarket.online/logo_quiz_answers_level_189kfktm.pdf
    • http://fullpisetc.ru/pmbok_guide_5th_editionjykkm.pdf
    • http://lollipopa.online/oxford_practice_grammar_basic_diagnostic_testdbkpy.pdf
    • http://lumosazef.iblogger.org/34051634622.pdf
    • https://cdn.sqhk.co/mixubiki/idzC9yd/fannie_mae_pre_foreclosure_sale_guidelines.pdf
    • http://nesobaka3.xyz/wow_assassination_rogue_dps_guide1b8et.pdf
    • http://raisinshq.club/internal_combustion_engines_applied_thermosciences_3rd_editionndxnq.pdf
    • http://waystep.site/gifafaxigilulojovunojiwuzjmkk5.pdf
    • http://copyrightsupporthelpcenter.com/30705602655g2ujx.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://bowukadosajolu.epizy.com/4660167451.pdf
    • http://gugamofizuxeg.epizy.com/83498887478.pdf
    • http://xoxewunifas.epizy.com/12164805372.pdf
    • http://durunorutap.epizy.com/80850165981.pdf
    • http://mubufelijora.epizy.com/39239432399.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010cf2.bin
90e50c2eb90c07ab0a44662a7c95e9dfa69c435c192114d2e6646417edc1bc5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x10CF2 5092 bytes
font_01_sfnt_off00011e54.bin
be739354c577607e9d36f5da6b5e5860c910360613990b0940da61913cafa19a
pdf-font-stream PDF embedded font (sfnt) at offset 0x11E54 10340 bytes