Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c2886d0f44aa536…

MALICIOUS

PDF

108.9 KB Created: 2021-05-18 15:14:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 04f7d49bd720916e5596d15f5a443afa SHA-1: 8c00d2e5abec7fe69efb2fa8e70c48cff494526a SHA-256: 2c2886d0f44aa536b6ef08170c88b11c41a2fbb73e5c4b4645274d1c56c941ad
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/strik?utm_term=free+download+game+pes+2019+ps2+iso PDF link annotation
    • http://jogubewuzamofet.iblogger.org/pusipeju.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4424405/normal_606380e8b4e92.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384482/normal_5fe67423a3159.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4407306/normal_602155b8d3139.pdfIn PDF document text
    • http://zufikolukak.22web.org/basic_accounting_terms_class_11_notes.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/7fdce0a2-01e4-453c-a79d-3ffda44a57b4/gcf_and_lcm_monomials_worksheet.pdfIn PDF document text
    • http://fepujevuzal.rf.gd/new_yorker_cover_january_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/967989ec-0d67-4c0e-8063-51fdb37fef13/kowofokuk.pdfIn PDF document text
    • https://s3.amazonaws.com/vabedafozo/54899638027.pdfIn PDF document text
    • http://jojanotesejivi.epizy.com/vopepirolizuzexinep.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b7309d6e-9aef-49ee-ab09-0bd1b28583e9/7750139843.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4d68c777-c010-4710-8aed-4950eb4d528f/free_python_tutorial_for_beginners.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e0f73dd1-ed6c-4553-9b2a-fc8dc2205259/cyberpunk_2077_ps4_price_walmart.pdfIn PDF document text
    • https://s3.amazonaws.com/jinabom/vatusokiwuwal.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f6123e17-4813-4a86-8bb2-6c63c5b72b24/13876706260.pdfIn PDF document text
    • https://s3.amazonaws.com/zozuxukoxo/dewemugixuruwegodaxofam.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/81638bd8-cce3-4338-97dd-7e65a9c97c65/dometic_fan-tastic_vent_roof_vent_model_3350.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001467f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1467F 5516 bytes
SHA-256: 32e93d31c33ffe0370b8e480434b568d82f6b52244535b5128118364eabe1c2f
font_01_sfnt_off0001592f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1592F 12640 bytes
SHA-256: 559ae07ef6a5287cd917bb311d48b19a66d429f5cdfcbd63a7c45a7ccb9b32ad
font_02_sfnt_off000182fe.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x182FE 16088 bytes
SHA-256: 97e8fdbbd6f7f3cc7c5be7fd2b67e2205d24646122122f1230a4e601f0c8c96a
font_03_sfnt_off000197bf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x197BF 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3