Malicious PDF — malware analysis report

Static analysis result for SHA-256 26011cdbd0a1c402…

MALICIOUS

PDF

145.6 KB Created: 2021-05-28 04:32:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 7c968d0b2e17e70490df43439b9d65b0 SHA-1: e3257c68345b84bdf88af423131e21d243cf2d6e SHA-256: 26011cdbd0a1c4023da9d73ba45c968065fb619b0ae14ee87d9ec5afe7c3f95c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that mimics a search result, likely to trick the user into visiting a malicious site. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were extracted, the PDF structure and embedded URI are sufficient to infer a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=how+much+does+catalina+os+cost PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4486042/normal_6004cd93cdb77.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4489440/normal_600659523ee27.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4457854/normal_60305b0e87c42.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4471960/normal_5ff6752cc6368.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417675/normal_6034dc738ccfd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4488092/normal_603df9290ba2d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421468/normal_604633b7e36cb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379217/normal_6066763f1d97e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385435/normal_60345ee842d6d.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/b2b53798-2eef-44cb-847e-c1db78a2a217/libro_de_fisica_2_bgu_maya.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/35d113f1-f48b-407c-bbee-7e0e2a13958e/59269625822.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1d738e52-bfac-4731-bcb0-20e30930b37e/stihl_battery_trimmer_fsa_56_reviews.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3dbe468f-6a4a-40e6-8125-06a0b205232b/65853478843.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4dabd6eb-b555-4d83-bf64-47fa582226f4/59466260857.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5be0abe9-dbe9-473e-a6a4-899a7fcd5224/on_the_road_again_movie_with_willie_nelson.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/90fc22f9-848b-4f32-88ce-29cb15f9eda6/how_many_calories_are_in_sonic_shake.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5f27f95e-52f5-4904-81a9-fb623d509d4d/a_woman_in_berlin_film_izle.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7b013329-b559-4761-bad6-eafb7cca3147/how_to_share_blogger_post_on_facebook_page_automatically.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00020219.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20219 5136 bytes
SHA-256: 05553a3d54eb9e2fb691b184bd4f360cdd3b9b14a5f15cfc6bfb0dad640a8c55
font_01_sfnt_off00021379.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21379 10996 bytes
SHA-256: 838d0c89772289842415d76d5bab5d2bd22e1593dc18218fc572972047f58d16