Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f944f089ed448a5…

MALICIOUS

PDF

77.7 KB Created: 2021-05-01 22:27:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e72f7a644bd18f85e8ca136e4706da8b SHA-1: 838e9a2d1431a71e48a8c339da6377ca41ca8004 SHA-256: 2f944f089ed448a5410eaef96ceac99dbcaa97f7ee4ecc34dd2de42cf4045880
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, seumenha.ru, which is likely used to host a phishing page or deliver a second-stage payload. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf' and a date, suggesting it might be a generated document used as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=child+of+god+cormac+mccarthy+quotes
    • http://dombitarf.ru/a_series_of_unfortunate_events_book_set_hardbacktutcx.pdf
    • https://static.s123-cdn-static.com/uploads/4417669/normal_5feffeaf591f5.pdf
    • https://cdn-cms.f-static.net/uploads/4401559/normal_60258e54ebcc7.pdf
    • http://tehnotop.site/can_democracy_survive_global_capitalism52mq6.pdf
    • https://cdn-cms.f-static.net/uploads/4382778/normal_602d8934621de.pdf
    • http://firstsecu-paypal.com/brother_hl-2270dw_driver_canadazydd8.pdf
    • https://cdn-cms.f-static.net/uploads/4401982/normal_603e6f730d18a.pdf
    • http://indir-kazan.com/how_to_draw_realistic_trees_without_leavestouz5.pdf
    • https://cdn.sqhk.co/lakivasulis/hi3jaha/rexosipizarulonulijuj.pdf
    • https://cdn.sqhk.co/govazofaj/hgjggjh/37572912942.pdf
    • https://cdn-cms.f-static.net/uploads/4483075/normal_60631003d1f30.pdf
    • https://cdn-cms.f-static.net/uploads/4451221/normal_5fdc198616e7b.pdf
    • https://cdn.sqhk.co/silutoge/e5xienx/deziwifukurujufa.pdf
    • https://cdn.sqhk.co/sawitofi/fqfHoih/entrepreneurship_and_innovation_course_description.pdf
    • https://cdn-cms.f-static.net/uploads/4391009/normal_6046b43195758.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c41e6de0-6922-4ea4-83f8-fb866e57f62d/tissot_t_touch_expert_solar_watch_price.pdf
    • https://uploads.strikinglycdn.com/files/d390d0c3-0986-4698-b45c-437ff934e207/3093568457.pdf
    • https://uploads.strikinglycdn.com/files/6072ba66-5716-4b52-8539-326e63441c91/63086949595.pdf
    • https://uploads.strikinglycdn.com/files/95e98736-0cce-4150-bae0-e37a01cffca4/92877466547.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000efc6.bin
d67271c7aa2c49e53c7ca33d47437a06599c531451d64a210dc62f52c5ad6326
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFC6 5568 bytes
font_01_sfnt_off00010287.bin
f9c403759486684fc95b0357b1028edb3670b659180af9b2e58995654d39d0cd
pdf-font-stream PDF embedded font (sfnt) at offset 0x10287 11060 bytes