Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c9288ca426abfa5…

MALICIOUS

PDF

91.5 KB Created: 2021-03-29 08:38:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 12e6a3ee06d8b3f097f421802a7e1af0 SHA-1: bbd0c83ba92c6d94a33221b13a25a2071dc3a545 SHA-256: 2c9288ca426abfa53f9f9d042dac4c53a183b04e18a06cfaf3ab8dbc5a9f8db2
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by ClamAV as Pdf.Phishing.Trojan. It contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may be instructing the user to open a password-protected archive, a common tactic to bypass security scanners.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/wix?keyword=introduccion+a+la+biblia+pdf+gratis
    • https://lenexemumuvag.weebly.com/uploads/1/3/1/4/131438583/nojetakubifubov.pdf
    • https://senamevab.weebly.com/uploads/1/3/4/6/134689233/1553097.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://f33d1b56-f518-462b-b61f-c1b5c1ba661c.filesusr.com/ugd/1c44ce_cce89652cccd404bbc1392fd17acef79.pdf?index=true
    • https://856cb5e6-6c81-45ce-9604-b57907a15cd2.filesusr.com/ugd/cc3ca9_713aab47136448d595062a76a311d74e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a598f15d-4846-4d13-91f4-a177e78e1190/how_do_you_remove_samsung_ice_maker.pdf
    • https://s3.amazonaws.com/xenavuxa/45596082925.pdf
    • https://7f993087-45f6-41f4-96e5-9dcaca18fb91.filesusr.com/ugd/9a92dd_14f3fe269a9b4b9ebca5ec071567db7b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/83dc540b-9296-434d-a820-b39430008853/logitech_z623_owners_manual.pdf
    • https://2f2ab42d-e0b4-4bd3-aa50-2430da1ff5fc.filesusr.com/ugd/eaf48f_aa2db666b62f4c799a2fff875ad83f5b.pdf?index=true
    • https://f7f2eb1f-4ce6-40bf-b337-6bcc2c9c1a95.filesusr.com/ugd/dc6899_e66d39d916ea4f3782b235a8f2960b22.pdf?index=true
    • https://uploads.strikinglycdn.com/files/554cd196-8cae-4806-9819-d4667f49c585/how_to_do_a_search_on_ipad_email_address.pdf
    • https://uploads.strikinglycdn.com/files/093fb6c7-8b66-4046-9ef0-fddd8a98c873/buvij.pdf
    • https://s3.amazonaws.com/pubopelej/violin_sheet_music_happy_birthday.pdf
    • https://s3.amazonaws.com/xapota/mozomef.pdf
    • https://6632aaff-1fe9-4f1d-acb3-7d444e457837.filesusr.com/ugd/ce4b7c_be77da4c7556416bb646acf8a342adb7.pdf?index=true
    • https://0b609444-e5a2-4a7e-9779-a3c6bae51a53.filesusr.com/ugd/529dbf_abd7f49299694c56b472f6155aff1958.pdf?index=true
    • https://s3.amazonaws.com/setaxilitozuko/dosajomudaporub.pdf
    • https://uploads.strikinglycdn.com/files/22203228-284f-4452-811f-b6dc041ad886/28133370874.pdf
    • https://uploads.strikinglycdn.com/files/7b44664a-f9d1-4804-8019-153d52d8f71a/the_world_in_6_glasses_how_many_pages.pdf
    • https://s3.amazonaws.com/legipalofi/zuwapobonu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000122e5.bin
04a4da6f1d5dab0f903067789ad52ae6ae98f5c37e59f1ad06db1b116c587d86
pdf-font-stream PDF embedded font (sfnt) at offset 0x122E5 5400 bytes
font_01_sfnt_off00013549.bin
7d800d012faf0efc50f44ac0a30da57ad5b47ea46fc77c2bd28c650ece6ed389
pdf-font-stream PDF embedded font (sfnt) at offset 0x13549 13016 bytes