Malicious PDF — malware analysis report

Static analysis result for SHA-256 2597582ff3e9ce8a…

MALICIOUS

PDF

86.3 KB Created: 2021-03-14 07:19:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f7f8fbeac1986c0c6743a8880d80ce7e SHA-1: 98072e8d2331691df1c7a915eac905c64f8d5d9c SHA-256: 2597582ff3e9ce8a851b61c03ab347e38e87b5473894fc0f30d300dd1fcc81ce
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. The document contains an embedded URL pointing to 'https://nipisod.ru/123?utm_term=buttery+adjective+form', which is likely a phishing site. No scripts were extracted, but the presence of the URL and the detection names suggest a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/123?utm_term=buttery+adjective+form
    • https://cdn-cms.f-static.net/uploads/4495395/normal_6034ec2f0df9d.pdf
    • http://pressit.fun/80381578408be30k.pdf
    • https://static.s123-cdn-static.com/uploads/4477408/normal_600066fc477ba.pdf
    • http://rimka.xyz/what_is_a_giant_star_astronomyctjdo.pdf
    • http://creamwalls.space/detolivedafesofw0svt.pdf
    • https://cdn-cms.f-static.net/uploads/4494430/normal_6027425330d4d.pdf
    • http://premiumpornclips.com/demonology_warlock_guide_bfa77him.pdf
    • http://yachts-4-sale.com/tovamigogdrqak.pdf
    • https://cdn-cms.f-static.net/uploads/4478688/normal_600c6eb917713.pdf
    • http://giocodigital.space/axial_and_radial_turbines_moustaphaj5tga.pdf
    • http://getsol.xyz/63476891603c7aed.pdf
    • http://insurancesouk.com/fobudopuwuzirodisakovo0436l.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nevowimo/83353363041.pdf
    • https://s3.amazonaws.com/veraxawewib/sample_test_cases_template_for_login_page.pdf
    • https://uploads.strikinglycdn.com/files/2b030b5f-721f-433e-98ed-dfe61435b8fe/star_wars_edge_of_the_empire_character_creation.pdf
    • https://uploads.strikinglycdn.com/files/0f0ea240-d4ee-43dd-a68b-5e54aefd5fea/how_much_does_a_580_case_backhoe_weight.pdf
    • https://uploads.strikinglycdn.com/files/842fa6f9-6b3d-4bd1-b861-31c927979935/67215651387.pdf
    • https://s3.amazonaws.com/pipaneku/seselo.pdf
    • https://s3.amazonaws.com/banula/mujebogozipinopafaton.pdf
    • https://s3.amazonaws.com/gagagakigibapo/rumene.pdf
    • https://s3.amazonaws.com/bifadiwuwileji/the_coso_internal_control_framework_identifies_five_internal_control_components.pdf
    • https://uploads.strikinglycdn.com/files/0b8afdab-ecb5-4a77-9820-1214fae44493/teverigapubaje.pdf
    • https://uploads.strikinglycdn.com/files/5fd4f7c5-b343-461f-98e2-e438ef4fc73e/what_does_str_mean_on_my_remote.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001148b.bin
a16957fac8b2bb8263dd73d450dc354f7b41a1c506f7d27c9a39f96b5646ed4c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1148B 5244 bytes
font_01_sfnt_off00012667.bin
688dfe85e9eb2413b08bca52064b98970e00b97dc6a287342bf0ffa65969cb72
pdf-font-stream PDF embedded font (sfnt) at offset 0x12667 10956 bytes