Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a14f2f15c183445…

MALICIOUS

PDF

78.3 KB Created: 2021-04-08 22:47:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cdb2c963f6cb6e20597e33e16a31a9f0 SHA-1: 214b6dd238aa272743d7ae0bec15fd1d754adc5e SHA-256: 3a14f2f15c18344581040dc05724d7b2d89dd35faf06a7b790495dbcca281570
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The document body, though heavily obfuscated, suggests a lure related to a vacuum cleaner manual. The presence of numerous external URLs, including one pointing to 'dafemum.ru', strongly suggests the document is designed to redirect users to malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=shark+navigator+powered+lift-away+vacuum+-+nv586+manual
    • http://rojibitakuvekuw.scienceontheweb.net/cartesian_coordinate_system_grade_8.pdf
    • http://polnews.xyz/14022928116kvrst.pdf
    • http://dutov.org/moxunt5gne.pdf
    • http://alkostore.xyz/626793586772ilzr.pdf
    • http://fortysgjdk.fun/nikon_sb-600_vs_sb-700_comparison9ogm9.pdf
    • http://simopuvoramawu.mywebcommunity.org/41417814143.pdf
    • https://static.s123-cdn-static.com/uploads/4383452/normal_6004dfc864d5d.pdf
    • https://cdn-cms.f-static.net/uploads/4456140/normal_6020c11362398.pdf
    • http://siondez.ru/descargar_traffic_racer_para_windows_7k8ub6.pdf
    • http://powerhdniy.space/751042297383ps77.pdf
    • http://jaralet.getenjoyment.net/difference_between_1_phase_and_3_phase_induction_motor.pdf
    • http://wowitaly.pro/kenmore_90_series_dryer_manual49p0f.pdf
    • http://electorat.org/72346390279crgyo.pdf
    • https://cdn.sqhk.co/kuniremolu/gchgcge/captain_marvel_hd_wallpapers_for_android.pdf
    • https://cdn-cms.f-static.net/uploads/4385613/normal_60246782128bf.pdf
    • https://cdn.sqhk.co/fozozumaj/jcjehgn/free_text_notification_sounds_for_android.pdf
    • http://pojibuvuj.mygamesonline.org/jeffrey_eugenides_the_marriage_plot.pdf
    • http://vumexovuvelafe.medianewsonline.com/how_to_fix_hp_cartridge.pdf
    • http://waranijovuv.sportsontheweb.net/totifubagojoxotonozanux.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://visunes.myartsonline.com/public_finance_and_public_policy_gruber_free_download.pdf
    • http://mozutulobiris.onlinewebshop.net/astm_a240_free_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0d9.bin
0ad7d373c8cdb9fb33340ba488dd5b33e75da5d09ae0af8b8e53438381615f46
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0D9 6316 bytes
font_01_sfnt_off0001065c.bin
efb19dade4ab6fce46747108a952dd113137e64037750088f12ba7fa0cf6f5d2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1065C 10748 bytes