Malicious PDF — malware analysis report

Static analysis result for SHA-256 22eb817db43f5872…

MALICIOUS

PDF

77.7 KB Created: 2021-03-23 19:46:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e3153342f9eff68f771e6ca2d7471ae4 SHA-1: 64c63fa34b0bae5e2e3f57e0157805e0f1b80d97 SHA-256: 22eb817db43f58727b1549dfd42b465bb95ae10cadfa9a034f2536c8c32c970a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'zajinet.ru', which is likely part of a phishing or malware distribution scheme. The document body, though partially corrupted, suggests a lure related to 'homemade garlic dipping sauce for pizza' to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=how+to+make+homemade+garlic+dipping+sauce+for+pizza
    • https://static.s123-cdn-static.com/uploads/4476427/normal_5fc5bbcba9056.pdf
    • http://vijexibat.mywebcommunity.org/zolopuvuretoruzukojo.pdf
    • https://cdn-cms.f-static.net/uploads/4489237/normal_601296b58c591.pdf
    • http://zuxekagapefe.mygamesonline.org/is_project_management_a_good_career_in_india.pdf
    • https://static.s123-cdn-static.com/uploads/4449419/normal_5ff2290a5628e.pdf
    • http://jotusimemirido.sportsontheweb.net/jefan.pdf
    • http://budijam.iblogger.org/aditya_hridaya_stotra_in_tamil.pdf
    • http://mopexaxurip.getenjoyment.net/baby_goat_yoga_orlando.pdf
    • http://dodisof.iblogger.org/what_is_basic_quantity_in_physics.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/1f119a58-288d-4d39-82d2-9578ed46fcb1/7244964548.pdf
    • https://uploads.strikinglycdn.com/files/a07d7b0d-998b-407a-b595-e855288142be/23801410414.pdf
    • http://riberudedanute.epizy.com/kiriri.pdf
    • https://uploads.strikinglycdn.com/files/3aedbba9-b3bc-42d7-a9c5-8aa8e219eafd/finitemu.pdf
    • https://uploads.strikinglycdn.com/files/2a1847ac-4ca5-4fcf-856b-b378f39ef868/pokifiloganufoma.pdf
    • https://uploads.strikinglycdn.com/files/67e2c182-87e6-4fbf-a204-9b5bf5e7f812/the_painted_bird_netflix.pdf
    • https://uploads.strikinglycdn.com/files/5a5993b6-aee1-4116-9455-48b98a61a97a/nojeritibobiminovozi.pdf
    • http://fufagagebo.epizy.com/shrek_movie_in_tamil.pdf
    • https://uploads.strikinglycdn.com/files/52f0e6a8-316d-4a5b-90c3-712c348e416b/filonoxiki.pdf
    • https://uploads.strikinglycdn.com/files/ab38848f-8b7a-4da9-8dee-bcb0195adc94/the_magus_ending_meaning.pdf
    • https://uploads.strikinglycdn.com/files/3d54fcbe-dcb8-4812-b84b-cd7015666a49/tosesojidevasemiwos.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed64.bin
57a4c8b621cbd9cbfe6762453ffa7afb16090b6bdde07a5116102385a5604ed7
pdf-font-stream PDF embedded font (sfnt) at offset 0xED64 5736 bytes
font_01_sfnt_off000100d3.bin
75d8349834dd31230779501f97ce6709abcbd00c4a0077827b12adf1d1d26601
pdf-font-stream PDF embedded font (sfnt) at offset 0x100D3 11220 bytes