Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c807f8a11fc771f…

MALICIOUS

PDF

78.9 KB Created: 2021-03-15 11:22:01 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 8478c6e66d3ee8fcb0ea23998a45d5f5 SHA-1: 8a3b1937d48adc4f12d94d2ff9d1d25338894830 SHA-256: 2c807f8a11fc771ff1a8740211363767ef6f2b1cc0da14526467857aad8895a2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'zajinet.ru', which is likely a malicious domain used to host phishing content or distribute further malware. The document body, though heavily obfuscated, appears to be a lure related to 'Apple cider vinegar makes teeth yellow', a common tactic to entice users to click on links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=apple+cider+vinegar+makes+teeth+yellow PDF link annotation
    • http://lowufadit.scienceontheweb.net/bogy_s_babca_virgai.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4405930/normal_5ffeaf66c9633.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4365660/normal_5fcb1cfae7411.pdfIn PDF document text
    • http://dnepr24.info/divinity_original_sin_weresheep6irpq.pdfIn PDF document text
    • http://saratov.ooo/zavozofapigekiwiz17bzg.pdfIn PDF document text
    • https://livadasim.weebly.com/uploads/1/3/4/3/134312527/2b26d5f2d476047.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4491673/normal_5ff5bedb86198.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403681/normal_604476bc85908.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4491426/normal_5ffda7df79fc7.pdfIn PDF document text
    • http://buvalopexur.mygamesonline.org/zofadiwavuzo.pdfIn PDF document text
    • http://medgaj.com/hidden_speakeasy_near_me2j9k1.pdfIn PDF document text
    • http://xalapuzim.sportsontheweb.net/domigusupagej.pdfIn PDF document text
    • https://xoxomedeze.weebly.com/uploads/1/3/5/3/135308121/manakaredarofakib.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://a3cd4400-5fdc-4e6a-bda8-88556a2d4d1f.filesusr.com/ugd/2f7489_d0c804ac763b437891208f30a44a1e88.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/viwoxuz/iriscan_anywhere_software.pdfIn PDF document text
    • http://juludiripo.myartsonline.com/25142461865.pdfIn PDF document text
    • https://s3.amazonaws.com/kawotexulozax/how_to_use_accu-chek_mobile_blood_glucose_monitor_system.pdfIn PDF document text
    • https://s3.amazonaws.com/gorajikunobixi/el_mundo_de_sofia.pdfIn PDF document text
    • http://malejubu.myartsonline.com/adhoc_sensor_networks_notes.pdfIn PDF document text
    • https://a1359116-1358-4cde-afc5-3600b4bb50db.filesusr.com/ugd/3b0c81_3b6145e1bd3641589edb2481c6a1d8c5.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF5DC 5796 bytes
SHA-256: 360cdbddee7ca2847346d74216045e06dfb638390037ef36abd0d2931f114ada
font_01_sfnt_off00010989.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10989 11088 bytes
SHA-256: 804f66322bc1ba19cb8dc937db1b1a839de3da90ee94a59d033f7d2cf24c74f4