Malicious PDF — malware analysis report

Static analysis result for SHA-256 26d4678be84e34c2…

MALICIOUS

PDF

77.0 KB Created: 2021-03-03 15:03:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 93e021106b9644063035c0e846f73fdd SHA-1: 4b3e77d6a0a004712a82d6d988a3a6e26f3a69ed SHA-256: 26d4678be84e34c21f584971ae946493a6528c180fb3cc1adc2e114482099dda
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of external URIs, specifically 'https://soxebez.ru/wix?keyword=terrible+things+piano', suggests a phishing or credential harvesting attempt. Although no scripts were explicitly extracted, the PDF format and embedded URIs are commonly used for delivering malicious content or redirecting users to exploit kits.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=terrible+things+piano
    • http://zajowidased.iblogger.org/path_of_exile_immortal_syndicate_guide.pdf
    • https://vexepediv.weebly.com/uploads/1/3/4/6/134668456/6726060.pdf
    • https://cdn-cms.f-static.net/uploads/4373240/normal_602ee4b2e5937.pdf
    • http://fovuvizoge.22web.org/tyt_th-9000d_programming_software_download.pdf
    • https://static.s123-cdn-static.com/uploads/4365662/normal_5fdeb0a0611a0.pdf
    • https://static.s123-cdn-static.com/uploads/4416796/normal_6007c793a901d.pdf
    • http://kefovatoxag.22web.org/bejox.pdf
    • https://static.s123-cdn-static.com/uploads/4383340/normal_600305da80be0.pdf
    • https://cdn-cms.f-static.net/uploads/4487419/normal_5fd8322fbcd08.pdf
    • https://febumade.weebly.com/uploads/1/3/4/7/134757335/xegapifowesisoba.pdf
    • https://febelozo.weebly.com/uploads/1/3/4/5/134599394/8391968.pdf
    • https://cdn-cms.f-static.net/uploads/4489057/normal_601b3aeb2f11d.pdf
    • https://ruwijupoxotafan.weebly.com/uploads/1/3/0/8/130814308/c0da0d9d738dd78.pdf
    • http://buliwomof.22web.org/businessman_2_full_movie_mkv.pdf
    • https://static.s123-cdn-static.com/uploads/4459645/normal_6001dbe13b844.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dixaleko/sermon_outline_about_the_lords_prayer.pdf
    • https://s3.amazonaws.com/batiku/mail_merge_template_word_2013.pdf
    • https://s3.amazonaws.com/jidosatikim/52923928612.pdf
    • https://s3.amazonaws.com/najubu/61289856324.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0f0.bin
9e8506d0ea31d9a88a53e0c215f07ff7acd2132157a8a7d1568de5d7d573f823
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0F0 5172 bytes
font_01_sfnt_off0001027b.bin
25af9bd6690b4f87f9ce9b6e00b79b1b3fae96def5c22a455db6ee772b513e07
pdf-font-stream PDF embedded font (sfnt) at offset 0x1027B 10672 bytes