Malicious PDF — malware analysis report

Static analysis result for SHA-256 25909f93e3c8cf29…

MALICIOUS

PDF

84.5 KB Created: 2021-05-21 01:21:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 41ff6b9e6483116a288cdab1753bcf5e SHA-1: e82051a38d89ec0ea6293fec8bcac93952cc01b6 SHA-256: 25909f93e3c8cf29cb0caef04e27ae26dd79511a518d3fcef886ef42354a1bb6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=oxido+de+bromo+vii+usos PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4443595/normal_604cbacd5507e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4468563/normal_604cb4636c4d8.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370273/normal_603c0294782a5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476758/normal_5fcc73f33e44a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4407576/normal_5fe117b3bedd7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4490367/normal_6019b490d7745.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375886/normal_5fd83b6c0b6f5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4443810/normal_5ff94249739ba.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447888/normal_600dbf9adbb59.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4419425/normal_5ff8f3298a1fe.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450336/normal_5fc76f7d3e177.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/ropidadegaxut/71198212025.pdfIn PDF document text
    • https://s3.amazonaws.com/zunewidimem/cats_and_dogs_full_movie_free.pdfIn PDF document text
    • https://s3.amazonaws.com/buwosevax/how_to_make_book_from_files.pdfIn PDF document text
    • https://s3.amazonaws.com/golepe/monetary_policy_questions_and_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/jewizopukuni/wunabolevugep.pdfIn PDF document text
    • https://s3.amazonaws.com/vixuwogetiv/ratio_analysis_project_report_ppt.pdfIn PDF document text
    • https://s3.amazonaws.com/bokofapig/bifocal_safety_glasses_near_me.pdfIn PDF document text
    • https://s3.amazonaws.com/rodiligarexo/4029279500.pdfIn PDF document text
    • https://s3.amazonaws.com/nilititonawafim/lazisanixerudu.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1e9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF1E9 5024 bytes
SHA-256: d00c5b11c03605baef8c3a5bb853d241d58acb646f3f870cbc8b3b640fec5a66
font_01_sfnt_off000102ee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x102EE 13112 bytes
SHA-256: cc3fe291dc950ca68db1d5fec696ad381a3d931645d2d4d772f0875f467074b4
font_02_sfnt_off00012d7f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12D7F 16260 bytes
SHA-256: d25a34a56be33791b66bd7dbe91ee772b39b89bee75ba0e64ef3ea6cb2c10b57