Malicious PDF — malware analysis report

Static analysis result for SHA-256 25bc128e346e1cd3…

MALICIOUS

PDF

223.3 KB Created: 2021-04-09 10:45:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: daa2de612e7be2421e0743b319037496 SHA-1: 73a4a331bc013e0deebae9ea05979866040e6e24 SHA-256: 25bc128e346e1cd3b865574909511f791a41b95b9538ade073c132ae68764067
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier, indicating malicious intent. It contains an embedded URI pointing to 'https://vilenefex.ru/strik?utm_term=cast+monster+island+2019', suggesting a phishing or redirection attempt. The document body, though heavily obfuscated, appears to be a lure related to 'Cast monster island 2019'. No scripts were extracted, but the presence of external URIs and the overall detection profile strongly suggest it's designed to lead the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9889

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=cast+monster+island+2019 PDF link annotation
    • https://cdn.sqhk.co/niserutom/hbjaS5Q/nifemelaxosoj.pdfIn PDF document text
    • https://luzibajaxu.weebly.com/uploads/1/3/2/6/132695572/8646106.pdfIn PDF document text
    • https://fumaletaseker.weebly.com/uploads/1/3/1/3/131381433/gikunuzelovaru.pdfIn PDF document text
    • https://cdn.sqhk.co/viwiratoposu/iigjVaa/57129063989.pdfIn PDF document text
    • http://mixit.info/fender_hot_rod_deluxe_price7nlw3.pdfIn PDF document text
    • https://tupivoxutod.weebly.com/uploads/1/3/4/4/134467409/mowogewokakime-ropovu.pdfIn PDF document text
    • http://blog-millionaire.buzz/48235035978vsw.pdfIn PDF document text
    • https://cdn.sqhk.co/pininipata/jeigoic/spanish_learning_books_free_download.pdfIn PDF document text
    • http://ses-paypal.com/womens_bodies_womens_wisdomnrnir.pdfIn PDF document text
    • https://bemozepe.weebly.com/uploads/1/3/0/7/130739793/5404407.pdfIn PDF document text
    • https://cdn.sqhk.co/nifijagik/gc7hcib/call_of_duty_warzone_mode_solo.pdfIn PDF document text
    • https://zeradukiw.weebly.com/uploads/1/3/4/8/134883462/3126043.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://21e323bd-7fdd-46e9-a6c7-4880e76d7610.filesusr.com/ugd/0a51c1_9573e315d309476e8488a70224ab3a08.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/donukadizolin/46493026675.pdfIn PDF document text
    • https://s3.amazonaws.com/wixamupelinere/counting_stars_piano_sheet_music.pdfIn PDF document text
    • https://1cbf0fd9-62af-4102-a3dc-982f361539e7.filesusr.com/ugd/bfbc46_749bc0221510465db1cb9412e03d17e8.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/nedijowewoded/dentist_that_perform_root_canals_near_me.pdfIn PDF document text
    • https://b5f169ef-6bcf-4d19-a24b-32bdc9dd7a5f.filesusr.com/ugd/2e79a6_9d5dad6e4de048648344a0aaadfcaf6f.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/xoxaneral/ansi_sql_standard_date_format.pdfIn PDF document text
    • https://s3.amazonaws.com/nolarifaforuxop/solving_quadratic_inequality_worksheet.pdfIn PDF document text
    • https://s3.amazonaws.com/desenaz/21983547653.pdfIn PDF document text
    • https://s3.amazonaws.com/sefepugolupalax/pharmaceutical_distribution_business_plan_india.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002b53e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B53E 31508 bytes
SHA-256: b399bb154cb0728998865365ab1d12245e8bfbb15b20017ffcb25cb21dd03c2b
font_01_sfnt_off00031903.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x31903 5356 bytes
SHA-256: fb8ec46c9084a148f42715f8ca3b256637f12aed41036fefd6e8b150ecaaa9cd
font_02_sfnt_off00032b15.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x32B15 14296 bytes
SHA-256: a9c222d9e1270c842d9a4cad32afe95891d9f96c58189652768696601dae2fef
font_03_sfnt_off00035804.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x35804 16132 bytes
SHA-256: 29a60492f44b39d68fa00197234d6df9a0cf581d74754725da64c153577ac146