Malicious PDF — malware analysis report

Static analysis result for SHA-256 3286ba7241c8a744…

MALICIOUS

PDF

73.0 KB Created: 2021-06-03 15:20:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d724047729db030a5fe7158af6d1db31 SHA-1: e1bbbd6ae31cbaef4e9133231bee16216f17a466 SHA-256: 3286ba7241c8a7445ce3c6743a5d921d7a00ce653e5de5fb25dd22af93067189
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is a PDF document flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier with high confidence. It contains an external URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The presence of a 'download button' heuristic further supports the attack pattern of luring users to download content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://philabc.ru/pbw?utm_term=army+battle+simulator+mod+apk+home
    • https://vituxusupodewe.weebly.com/uploads/1/3/1/3/131379836/b398da22104e027.pdf
    • https://watuxiso.weebly.com/uploads/1/3/2/7/132740831/mewetiwebutafifadu.pdf
    • https://samarobiratepiw.weebly.com/uploads/1/3/5/3/135327643/6803142.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f3a4628e-3a5a-4c2e-95c1-3e88a4fb9a27/troy_bilt_tb575ec_fuel_line_diagram.pdf
    • http://famukaser.pbworks.com/w/file/fetch/144423603/fajetedapawokevoxamupolo.pdf
    • http://liwuvedesisu.pbworks.com/w/file/fetch/144492507/9.pdf
    • http://wuvebag.pbworks.com/w/file/fetch/144428844/fundamentals_of_management_8th_canadian_edition_free.pdf
    • http://gonumutat.pbworks.com/w/file/fetch/144557451/how_do_i_clean_the_filter_on_my_samsung_microwave.pdf
    • http://faxamom.pbworks.com/f/65731205349.pdf
    • http://tisowowuduwe.pbworks.com/f/28667186608.pdf
    • https://uploads.strikinglycdn.com/files/3f2fa78b-4712-451f-9a44-b5a45af5cf5b/mutupaterofazesimoj.pdf
    • http://kufogokoges.pbworks.com/w/file/fetch/144561039/bosofisazasuma.pdf
    • http://lakebimutep.pbworks.com/w/file/fetch/144418044/57230635203.pdf
    • http://banusiv.pbworks.com/w/file/fetch/144446733/soul_surfer_full_movie_english_free.pdf
    • https://uploads.strikinglycdn.com/files/ac444f12-03bb-4298-8d52-b97ffe732394/70113097905.pdf
    • http://mujefapufefi.pbworks.com/f/the_loudspeaker_design_cookbook_download.pdf
    • https://uploads.strikinglycdn.com/files/b9b7b9c5-5c8f-4c41-bf32-f6b818ee9dbe/tutorialspoint_css_editor.pdf
    • http://zopujoxobug.pbworks.com/f/angry_neighbor_apk_indir_android_oyun_club_son_srm.pdf
    • http://gajufabeke.pbworks.com/w/file/fetch/144423336/80452781275.pdf
    • http://lugozamuxika.pbworks.com/w/file/fetch/144412446/69957912064.pdf
    • https://uploads.strikinglycdn.com/files/e706d2d0-f8e5-40f3-8436-c325fc41e5ac/71705634566.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dbb4.bin
b4324dd715ba21caf24ff2bce4f0a4a6b909130fa6445beb2342924ea29f5586
pdf-font-stream PDF embedded font (sfnt) at offset 0xDBB4 5492 bytes
font_01_sfnt_off0000ee34.bin
2c076f3bbfa02224e1d10aef1af29511052d7e7bf9543c826d05c64d7fe041b5
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE34 12636 bytes