Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c73358e78d9044a…

MALICIOUS

PDF

285.2 KB Created: 2021-04-02 11:10:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: a7b84927327faba960c5775ca34dc04e SHA-1: 7216ddba4a42df2c30f43b3e03169a22e7c5f18e SHA-256: 2c73358e78d9044a89ed02f64fa603607fb80775950d0c9e218b625f757c7477
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9613

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/award?keyword=barbara+oakley+books+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4369158/normal_602d77c233e01.pdfIn PDF document text
    • http://likelid.xyz/real_boxing_2_rocky_cheatslvkq7.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4460473/normal_5fe1596641244.pdfIn PDF document text
    • https://cdn.sqhk.co/zepipawetopi/YwZicjb/gasepibakefexezuwini.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4481161/normal_600033da8e2b7.pdfIn PDF document text
    • http://fortuneocredit.com/gofatamivadovokoninxrb3c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4479454/normal_605dc286e44e3.pdfIn PDF document text
    • https://cdn.sqhk.co/kabawamurelo/WciihfK/sepexavatutako.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4488807/normal_6044f4424cdaa.pdfIn PDF document text
    • https://cdn.sqhk.co/fesakesovoka/oUdCKig/blocky_gun_paintball_silver_games.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4473432/normal_605f48c803b7c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4451753/normal_6008a8c23c841.pdfIn PDF document text
    • https://cdn.sqhk.co/wabajevebe/ieijCjh/draw_lines_of_symmetry_for_these_designs.pdfIn PDF document text
    • https://cdn.sqhk.co/kizajituxab/GPqiaha/tank_battle_war_commander_online.pdfIn PDF document text
    • http://discovljzg.fun/kikadugumemuvatubajoumdb9.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/c2b40fa5-b3b9-4a39-b266-d18075c27bc4/mazofowaterapubame.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a13859c1-4593-4cf5-8d0b-d0dcb7d8641c/xeseforog.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e8766b20-6ef9-45ec-8071-d60b82530f39/82024365815.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/757d61ec-bcc2-4dad-8b23-46da5d876b0e/78059051344.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000412ff.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x412FF 4944 bytes
SHA-256: 047f0226fb71af239b47103c3918147ca069d0512e87e570a2712adaab45a32d
font_01_sfnt_off000423df.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x423DF 1800 bytes
SHA-256: daad3f347a4f42f432ee9983e619a7c063e36761dba5934b469418034847e28e
font_02_sfnt_off00042c6d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x42C6D 13372 bytes
SHA-256: 18a16b70a2cc6de705cf177111d739ffd107ad022778b4df7e4725c7a0604ebc
font_03_sfnt_off0004574c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4574C 4324 bytes
SHA-256: 1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361