Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f6ca4cbc0c0bd48…

MALICIOUS

PDF

91.3 KB Created: 2021-03-18 14:37:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 83c31ff8b6b4e39fd062ca399c64d28b SHA-1: ed1f2d394b32ec690cad8dba6be20d9f5f74f987 SHA-256: 2f6ca4cbc0c0bd487a2a1bd34549322028fe2f884d5ef846830ea42d7042640c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded URLs that lead to suspicious domains, and the ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, suggests a lure related to a fitness product manual, likely to trick users into visiting a malicious site. The presence of external URIs and embedded URLs points towards a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=stamina+r360s+recumbent+bike+manual
    • https://silatasetexa.weebly.com/uploads/1/3/1/6/131637876/4642484.pdf
    • http://quickpapp.online/nuraniruxewidofemw33ug.pdf
    • http://uniques.space/broccoli_sprouts_nutritional_informationces55.pdf
    • http://keksik24.ru/3571077241661bv6.pdf
    • http://dvigatel.guru/ssc_maths_algebraeaf0e.pdf
    • https://xovonugobo.weebly.com/uploads/1/3/4/6/134688771/9516420.pdf
    • http://rat-red.space/fepopalibufuboxawategdmyo.pdf
    • https://peretokat.weebly.com/uploads/1/3/4/0/134040551/lemelegim_wexipivumij_naxaridobuwefa_rogedasuf.pdf
    • https://cdn.sqhk.co/tokebamojos/ajhyYig/luluwomivekaranuzereme.pdf
    • https://vebuwume.weebly.com/uploads/1/3/5/3/135349689/72be9482.pdf
    • https://cdn.sqhk.co/vujaderaz/hgheXi6/65112827074.pdf
    • https://cdn.sqhk.co/kofatuziwu/jigichj/98452246392.pdf
    • https://zomerasojukoluw.weebly.com/uploads/1/3/4/7/134769652/7514185.pdf
    • https://cdn.sqhk.co/fufitefan/ghifBnU/14045773136.pdf
    • https://cdn.sqhk.co/pafatewodoju/hbCQfgj/sawewiwijetuvixav.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://lifarodanudu.rf.gd/battle_trip_twice.pdf
    • https://s3.amazonaws.com/zamemigojat/stalker_call_of_pripyat_weapon_upgrade_guide.pdf
    • https://s3.amazonaws.com/rawesaragegugar/79619630083.pdf
    • https://uploads.strikinglycdn.com/files/e975ec2a-06d4-4dd4-8e5f-a6e91f92c3ec/22100042553.pdf
    • https://s3.amazonaws.com/zubuwujoxom/bhaiya_song_masstamilan.pdf
    • https://uploads.strikinglycdn.com/files/f125df61-31a6-4429-80c2-e6710a7519fb/dozigefanul.pdf
    • https://uploads.strikinglycdn.com/files/4e51210b-dadc-44de-8113-2a23fef242d8/tomugaweweliri.pdf
    • https://uploads.strikinglycdn.com/files/60bbeecc-e297-49cb-aa51-1c55bacaf162/how_to_set_personal_goals_at_work.pdf
    • http://putajisuguxavul.rf.gd/andromache_play.pdf
    • https://uploads.strikinglycdn.com/files/5dd473f6-2c69-491c-ad33-e5d32d86d40f/how_to_use_walgreens_ear_thermometer.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00013623.bin
84ded29ff15bbfedfebd8ba5578c22b82fa041412c70bf4a191cb8080763ac5c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x13623 23304 bytes
font_00_sfnt_off0000fb5e.bin
b6f2c653501114d02332c666000beec55ae73b6c205d4d4169129c91fd25feb5
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB5E 5712 bytes
font_01_sfnt_off00010eae.bin
eaf2d9da3fe27709d9b9a3a878316463d2d29a3e233586e0c8d33c755d99ba94
pdf-font-stream PDF embedded font (sfnt) at offset 0x10EAE 11476 bytes