Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ef74644436f7428…

MALICIOUS

PDF

92.3 KB Created: 2021-05-05 15:28:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d6852d0ecc720fda7163a3545892a0ce SHA-1: 793a5ea11c043ebd31d2e2a48284b569c920e4b4 SHA-256: 2ef74644436f7428473e6c4cf78c96a94343d89a151dfedd65b23ebbb42371df
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, identified by the PDF_URI heuristic. The ML classifier and ClamAV detection strongly indicate maliciousness. The embedded URL, https://botokaw.ru/strik?utm_term=ti-nspire+cx+ii-t+cas+review, is likely used for phishing or to download a secondary payload. No scripts were extracted, but the presence of external links in a PDF is a common tactic for distributing malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=ti-nspire+cx+ii-t+cas+review
    • https://cdn.sqhk.co/wexifidobafo/bjfhn0K/buvedifava.pdf
    • http://reactivaperu-viabcpi.com/85297116673xrcz5.pdf
    • http://nipizakevenuvis.scienceontheweb.net/5385904885.pdf
    • https://cdn.sqhk.co/jenotefi/jebh7ii/wasutapijerebu.pdf
    • http://polystate.ru/orbit_1_output_port_digital_hose_end_timer_manual0pik2.pdf
    • http://fudoviwil.mywebcommunity.org/badareliloxod.pdf
    • https://cdn.sqhk.co/lojegalivo/FLTiesp/37499066789.pdf
    • http://zoomita.fun/82267169310lp9u7.pdf
    • https://cdn.sqhk.co/dodufiruw/jd0hbgh/zugapasopapu.pdf
    • http://fijexojor.getenjoyment.net/payment_of_gratuity_act_rules.pdf
    • https://cdn.sqhk.co/gixotagokezu/tjjgdba/reveravomuzemogoduxubu.pdf
    • https://cdn.sqhk.co/loberutebe/jhKgdhi/walumakajevawifixosadag.pdf
    • https://cdn.sqhk.co/nuzinirumawe/dgdXhbs/sevigenikiwurizolubow.pdf
    • http://help-feedback-amzn6.xyz/ham_radio_license_study_guiderqsyu.pdf
    • https://cdn.sqhk.co/ziloteduxemo/IhjHsGc/27938518485.pdf
    • http://goodshopsales.xyz/95669624057w4gan.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fomepufasele.atwebpages.com/toyota_automatic_transmission_service_manual.pdf
    • https://s3.amazonaws.com/zukogi/tokebijabupe.pdf
    • https://s3.amazonaws.com/vovuzize/weapons_of_math_destruction_summary_chapter_6.pdf
    • https://s3.amazonaws.com/jizubisetebof/rutujixozevovetidowap.pdf
    • https://s3.amazonaws.com/sumesawoxajew/equipment_installation_report_template.pdf
    • https://s3.amazonaws.com/kotodur/romobazixufi.pdf
    • https://s3.amazonaws.com/rujimidujek/sat_math_tips_2019.pdf
    • https://s3.amazonaws.com/tamobalasu/android_sqlite_column_types.pdf
    • https://s3.amazonaws.com/pirofopafu/long_division_with_decimals_worksheets_with_answers.pdf
    • https://s3.amazonaws.com/bisiku/how_to_turn_on_sony_soundbar_without_remote.pdf
    • https://s3.amazonaws.com/jinabom/31748727541.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000129b5.bin
6acc42279b60679e8724cfdadbee2283cd0f34c51ffd16b061b31a2ebd8bf75a
pdf-font-stream PDF embedded font (sfnt) at offset 0x129B5 5096 bytes
font_01_sfnt_off00013b35.bin
b6d3056778150d65721e31b11be5f636d69e2372cfa1476941ccd3bde0c521f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x13B35 11432 bytes