Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d0fadb9cb9dbd37…

MALICIOUS

PDF

72.9 KB Created: 2021-04-08 12:44:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 1400b008be30981c5ad03dc56f9afde0 SHA-1: 0ecf9aed0f7bf649c0dc363941dae858be8ee88c SHA-256: 2d0fadb9cb9dbd37b30d994758e3e64e13f9ac992fd8f72b021f780eb97e6f49
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=vermont+casting+intrepid+stove+for+sale PDF link annotation
    • https://cdn.sqhk.co/nisosawero/Bhagi9y/litorojawinesavopupebusi.pdfIn PDF document text
    • http://tronreserve.online/thule_roof_rack_jeep_grand_cherokee_2020dezqy.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372399/normal_600a543d68cde.pdfIn PDF document text
    • http://gtmedis.com/animated_ppt_template_freerokxm.pdfIn PDF document text
    • https://cdn.sqhk.co/niripakexad/djeHJje/4142630463.pdfIn PDF document text
    • https://cdn.sqhk.co/revinoxu/hzuBghi/sun_easy_racer_recumbent.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4468270/normal_603e091a6f139.pdfIn PDF document text
    • http://klossheff.xyz/applied_statistics_and_probability_for_engineers_6th_edition_international_student_version7m76j.pdfIn PDF document text
    • http://mitefakosutupot.22web.org/which_bags_are_recyclable.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412778/normal_605f9026cbc98.pdfIn PDF document text
    • http://nuwenipo.22web.org/wuledaronet.pdfIn PDF document text
    • http://coolmag.biz/14550534337vyom5.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/nuselufuzo/10986992589.pdfIn PDF document text
    • http://jajowisomipuw.epizy.com/igcse_biology_topical_past_papers_with_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/sowewazulejewi/bose_earbuds_wireless_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/jokotaziweluge/cisco_cisco2901-v_k9_eol.pdfIn PDF document text
    • https://s3.amazonaws.com/diwitapezu/burnout_3_takedown_pc_completo.pdfIn PDF document text
    • https://s3.amazonaws.com/litunux/citadel_forged_with_fire_starting_guide.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dfdf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDFDF 5500 bytes
SHA-256: eb41eb7cd9fc7f8d5ff40f7ad05e61ec682773f1d9da261a2f62cd268a425128
font_01_sfnt_off0000f291.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF291 10436 bytes
SHA-256: d7f847fc5707ca6afaed6e78a6e3f680e16f4f4858cd45ecb7f3cf4d932f6dd4