Malicious PDF — malware analysis report

Static analysis result for SHA-256 3875db87bdd25ac4…

MALICIOUS

PDF

78.5 KB Created: 2021-03-23 17:07:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 80b08e2a36f101b9892a5fe0ee0a0904 SHA-1: e2667d86220c459fe5a97e6033a23f678dd7538d SHA-256: 3875db87bdd25ac4c76ac278bf2a99a7ed0fe8c34066c2466beca027ba91f1cb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The embedded URL, https://botokaw.ru/wix?keyword=ed+reverser+ingredients, is likely used to deliver a malicious payload or redirect the user to a phishing site. The document body, though heavily obfuscated, contains text related to "ed reverser ingredients", suggesting a lure to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=ed+reverser+ingredients
    • http://adanakebap.org/xabemimuzlxai4.pdf
    • https://static.s123-cdn-static.com/uploads/4415327/normal_5fca43b79c63a.pdf
    • https://cdn-cms.f-static.net/uploads/4380214/normal_600fea1ed9c85.pdf
    • http://thrivewebs.com/6627517522183d9.pdf
    • http://reassurez-moi-fr.info/is_hamilton_beach_a_good_toaster_ovenqoby6.pdf
    • http://muziwavesos.iblogger.org/calcium_metabolism_in_dentistry.pdf
    • http://jakartapro.xyz/operaciones_combinadas_con_fracciones_1_eso_vitutor828gv.pdf
    • https://cdn-cms.f-static.net/uploads/4377931/normal_6022550de041a.pdf
    • http://creampiepow.club/822072384143b22s.pdf
    • http://murezisafedamaw.22web.org/65829938761.pdf
    • http://besudigedabax.iblogger.org/this_is_amazing_grace_chords.pdf
    • http://gulivopaduro.22web.org/baermann_clarinet.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fazafof.rf.gd/kosari.pdf
    • http://vedezanopade.epizy.com/demusilamuxa.pdf
    • https://63f3b980-df56-4d16-8c75-de9131d8e0d8.filesusr.com/ugd/b7fdcf_d3fce80c627e4d0fa1406f49e6ac2559.pdf?index=true
    • https://7c8f45b7-e058-4e27-bccd-8ee7dcb26900.filesusr.com/ugd/d5cf39_eb91fabfa3c142859ce0a370a628c894.pdf?index=true
    • https://0b7b936c-93ac-4a60-9644-6ba220b934cc.filesusr.com/ugd/b4bf80_3033ef8dce624e0d8b558868e387b5dd.pdf?index=true
    • https://b46c4cda-4951-41c0-816f-bbf02eee4d9b.filesusr.com/ugd/4ff992_c8d1a444fe2c43ab9100db360063d249.pdf?index=true
    • http://xafonabikox.rf.gd/lab_report_10_integumentary_system.pdf
    • https://s3.amazonaws.com/xajowu/36282706709.pdf
    • https://s3.amazonaws.com/jemazejodep/vizerepodorafagagalaji.pdf
    • http://matunojusorim.epizy.com/at_cafe_6_360p.pdf
    • http://kosejoviwo.epizy.com/how_much_does_a_tesla_engineer_make.pdf
    • http://mefadagisi.rf.gd/fimiwa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f76a.bin
c1a64ccddcdba11295a582ccd3757cb8a6335a3e3b03af2cc8d72c72b1b72f15
pdf-font-stream PDF embedded font (sfnt) at offset 0xF76A 4768 bytes
font_01_sfnt_off000107b8.bin
78470484dfd724646f3d29acfbdfd99ece56a00a61a769da288562ea75fb7297
pdf-font-stream PDF embedded font (sfnt) at offset 0x107B8 10816 bytes