Malicious PDF — malware analysis report

Static analysis result for SHA-256 393d1ff421557c74…

MALICIOUS

PDF

113.4 KB Created: 2021-02-28 21:24:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b044747d71c5ce77e121a96ba18607b6 SHA-1: 5c65a127d18dcecd80553acb85d435b8d731f20d SHA-256: 393d1ff421557c7411388ce05dd3d7f5cffc1d9f68bcabb15ad3b7622e7f4c73
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. The embedded URL, 'https://botokaw.ru/123?utm_term=el+libro+de+los+muertos+4+pelicula+completa+en+espa%25C3%25B1ol+latino', suggests a lure related to a movie title to entice users to click. While no scripts were explicitly extracted, the PDF structure and the nature of the URL indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=el+libro+de+los+muertos+4+pelicula+completa+en+espa%25C3%25B1ol+latino
    • https://static.s123-cdn-static.com/uploads/4414864/normal_5fcc1c64c42cb.pdf
    • https://cdn-cms.f-static.net/uploads/4388280/normal_602d99a735652.pdf
    • https://cdn-cms.f-static.net/uploads/4403819/normal_5fd2218def97f.pdf
    • https://cdn-cms.f-static.net/uploads/4379984/normal_5fe97eb101548.pdf
    • https://cdn-cms.f-static.net/uploads/4403679/normal_60130b8100c85.pdf
    • https://cdn-cms.f-static.net/uploads/4487419/normal_6010468e7d0fe.pdf
    • https://cdn-cms.f-static.net/uploads/4370319/normal_60167d33617cd.pdf
    • https://cdn-cms.f-static.net/uploads/4501991/normal_5fd71bbb2775d.pdf
    • https://static.s123-cdn-static.com/uploads/4366340/normal_5feedc0a35303.pdf
    • http://santecmb-sarl.com/17967126590vufiu.pdf
    • http://arevakar-travel.com/symless_synergy_freee93az.pdf
    • http://mufutekuson.getenjoyment.net/68899215022.pdf
    • http://anarchymedya.com/231430035214uvtp.pdf
    • https://static.s123-cdn-static.com/uploads/4368488/normal_5ff320c9713a9.pdf
    • https://cdn-cms.f-static.net/uploads/4427793/normal_6018ac6892350.pdf
    • https://cdn-cms.f-static.net/uploads/4423454/normal_5fd0db3757ad4.pdf
    • https://static.s123-cdn-static.com/uploads/4484126/normal_5fcddf96f1b87.pdf
    • https://static.s123-cdn-static.com/uploads/4493890/normal_5fe456152a9e0.pdf
    • https://cdn-cms.f-static.net/uploads/4488330/normal_6031863ed1faf.pdf
    • http://zdorovienashevse.xyz/nojudosofov3vyg0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zorijefugixor.atwebpages.com/rode_videomic_pro_battery_change.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off000183c9.bin
56ff6d64868ee5a3a0a4357bf8b345e817ed0dc73b822c1eaf2e356bcd20691a
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x183C9 27700 bytes
font_00_sfnt_off00014901.bin
c21e49cb2c49e8573540332b1fd6a7cea821fc063dfd826bc18445112ce5bb8f
pdf-font-stream PDF embedded font (sfnt) at offset 0x14901 5616 bytes
font_01_sfnt_off00015bb8.bin
a55e91baa45523f5b8466e9cbc079a029bb98fc7b8c71ab7bb85576d24c405e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x15BB8 12340 bytes