Malicious PDF — malware analysis report

Static analysis result for SHA-256 23951023ccfd2b44…

MALICIOUS

PDF

106.7 KB Created: 2021-01-25 21:55:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-17
MD5: 0ef999e495b490a7ba513127f00bf716 SHA-1: d9c693d2261fcd676674af2cba3e700a1e06c877 SHA-256: 23951023ccfd2b449c2fad0d7371ec9849a5b151f258764fdcc523e75a717c21
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple invisible and repeated links designed to trick the user into downloading a payload. The primary malicious URL identified is https://leonvi.ru/123?utm_term=jacquie+lawson+cards.com, which is associated with payload delivery. While no scripts were explicitly extracted, the PDF structure and the presence of embedded URLs strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LURE
    PDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/123?utm_term=jacquie+lawson+cards.com In PDF document text
    • https://cdn.sqhk.co/gufezitaxato/dOhhhfQ/smart_bomber_bomber_friends_apk.pdfIn PDF document text
    • https://cdn.sqhk.co/vawapisoxe/hjChbhf/ice_cream_shops_near_delray_beach.pdfIn PDF document text
    • https://cdn.sqhk.co/diwiporeb/Iihih2a/trading_neon_black_scooter_adopt_me.pdfIn PDF document text
    • https://cdn.sqhk.co/kimamena/0CvihWp/drawing_charades_online_game.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4418984/normal_5fd635e221b52.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4447098/normal_5fc862d5b8b4d.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4405642/normal_5fe3232b61494.pdfIn PDF document text
    • https://cdn.sqhk.co/fasotaluvose/ibiiqhj/rush_rally_3_switch_review.pdfIn PDF document text
    • https://cdn.sqhk.co/wavefekus/IhgIGgh/70279019496.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403563/normal_5ff758ada45c0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/vitelitubovuluj/87774069777.pdfIn PDF document text
    • https://s3.amazonaws.com/timituvupame/45675090436.pdfIn PDF document text
    • https://s3.amazonaws.com/xalasawu/butterfly_valve_catalogue.pdfIn PDF document text
    • https://s3.amazonaws.com/xajowu/rorerimodu.pdfIn PDF document text
    • https://s3.amazonaws.com/sagotomagin/cartoon_app_for_android_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://www.jacquielawson.com/?source=jlfb&utm_source=facebook&utIn PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000150d6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x150D6 5324 bytes
SHA-256: 7d0920c636c041ac5345df542646783c736b3a03a746e0b87f1808f358e55f74
font_01_sfnt_off000162e9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x162E9 10780 bytes
SHA-256: ac0713a09cdeec922b9b85f104569e5b9490098369128856a8d694bcf9dfd246
font_02_sfnt_off00018703.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18703 16068 bytes
SHA-256: 03a5ddad4a2a9171a93ce60914583e3601ab986f29a2c4cb248efc8e19c0a50a