Malicious PDF — malware analysis report

Static analysis result for SHA-256 352026d47ff0c7ce…

MALICIOUS

PDF

72.4 KB Created: 2021-03-27 11:19:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 91f33fba6fa72eb21149cb3ff4150986 SHA-1: 72a3aac9ad5799679f7bb7cbb8462f2bca8b9eda SHA-256: 352026d47ff0c7ceb7a22611d3b0576d0daa89b4131e3b9856367c6dff232835
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, 'xezojetit.ru', which is likely used to host a malicious payload or redirect to a phishing page. The document body is heavily obfuscated, but the presence of the external URI and the high risk score indicate a malicious intent to compromise the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=android+recyclerview+selection+mode
    • https://static.s123-cdn-static.com/uploads/4412996/normal_5ffffe944daa2.pdf
    • https://static.s123-cdn-static.com/uploads/4481275/normal_5ff2b9e47c5be.pdf
    • https://static.s123-cdn-static.com/uploads/4423454/normal_600913ea3b0b2.pdf
    • http://timurberg.ru/30179837314nwn0g.pdf
    • http://kismyketio.com/the_shack_netflix_casta359f.pdf
    • https://static.s123-cdn-static.com/uploads/4386347/normal_5fce5ddcd6489.pdf
    • https://cdn-cms.f-static.net/uploads/4445115/normal_605162453ec2c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/6ef65970-011b-4d8c-b166-e94dfdd57cc5/gelifopewutosugowanafo.pdf
    • https://uploads.strikinglycdn.com/files/08e513cc-863d-4d6d-9ac8-dcd2e8a23751/moviemaking_merit_badge_pamphlet_download.pdf
    • https://uploads.strikinglycdn.com/files/27657bb2-6242-494a-be63-62100b9f6f8c/36109451625.pdf
    • https://s3.amazonaws.com/nitajosasa/ziwajixemotibotoxuv.pdf
    • https://s3.amazonaws.com/xijuxosisomuna/islands_of_decolonial_love_online_free.pdf
    • https://s3.amazonaws.com/kegovev/toni_morrison_sula_characters.pdf
    • https://s3.amazonaws.com/lowuwofuxali/pezazoluvetewexed.pdf
    • https://s3.amazonaws.com/wovugi/87733248286.pdf
    • https://s3.amazonaws.com/zamemigojat/dutasotowepu.pdf
    • https://uploads.strikinglycdn.com/files/c630bf11-ef2a-4c51-890d-29552953beca/67755845537.pdf
    • https://uploads.strikinglycdn.com/files/1376e1e6-f465-431d-9e34-1882127d0a06/hp_elitebook_8570p_i7_release_date.pdf
    • https://s3.amazonaws.com/pusori/alphabet_tracing_worksheets_for_kindergarten.pdf
    • https://uploads.strikinglycdn.com/files/09edd516-c991-42d3-8217-eb65dd06e3b2/66888671388.pdf
    • https://s3.amazonaws.com/loxopudizus/emerson_self_reliance_rhetorical_analysis.pdf
    • https://uploads.strikinglycdn.com/files/76f7e01f-b5e2-4210-a804-d6e1d334fced/25500318312.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dca2.bin
350b3079a0b296f8ac03161acb0df880b4efdb1be7b4f06fe5a4c2fcb0b824cc
pdf-font-stream PDF embedded font (sfnt) at offset 0xDCA2 5116 bytes
font_01_sfnt_off0000ee11.bin
bfc2c9a14b201ea2169443ad274c69071c21fe8c3447855d68178aaaaad13578
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE11 10556 bytes