Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a8f521634975ce4…

MALICIOUS

PDF

73.9 KB Created: 2021-03-03 15:24:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 049820da61c12e1d1ea6108b5472aece SHA-1: 2660b3830d9d945e379cfc5993628fb323729769 SHA-256: 3a8f521634975ce450ebd52282f0d92a7aa38fa8825e1e7591cb022d1ed49814
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, which is likely intended to redirect the user to a malicious website. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan. The document body, though heavily obfuscated, suggests a lure related to a search query, aiming to trick the user into clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=orange+and+yellow+make+what+color
    • https://cdn.sqhk.co/nivavepe/iajbrgd/95841982327.pdf
    • https://cdn.sqhk.co/purilusevike/ehfnXCf/download_hi_q_mp3_recorder_apk.pdf
    • https://cdn.sqhk.co/nesadatifu/gjGvA2n/ea_sports_ufc_4_career_mode_guide.pdf
    • https://cdn.sqhk.co/kapipota/bkia2nT/73559678072.pdf
    • https://cdn.sqhk.co/ritasuxa/vwbVTig/19239533748.pdf
    • https://cdn.sqhk.co/xaloridinef/HPjbtjg/download_game_pocket_academy_zero_mod_apk.pdf
    • https://cdn.sqhk.co/muvotugi/fYoifRD/goperisezumegenijexeko.pdf
    • https://cdn.sqhk.co/fekawitaxug/YHii6Zt/rare_pokemon_cards.pdf
    • https://cdn.sqhk.co/fazejitev/nidhdgf/pocket_city_free.pdf
    • https://cdn.sqhk.co/dilizilozok/fhdiigh/hide_and_seek_game_no_download.pdf
    • https://cdn-cms.f-static.net/uploads/4468823/normal_6017104f53278.pdf
    • https://cdn.sqhk.co/dabozijide/gfiijf1/74527267564.pdf
    • https://cdn.sqhk.co/dolafita/Sohhhgo/performing_arts_center_milwaukee.pdf
    • https://cdn.sqhk.co/rasepotobami/ChsMggk/66065764676.pdf
    • https://cdn.sqhk.co/goxepijikun/gdkfsw8/drivetime_cars_downey.pdf
    • https://cdn.sqhk.co/lokalofobox/jb2UheV/kedatasiwidozimofetikasar.pdf
    • https://cdn.sqhk.co/bozawenibiwa/jgyiehf/24428172164.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://juxugalipexobow.epizy.com/carlow_county_council_housing_application_form.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e405.bin
3b3cd7ffa9a1d698ad502a9c439c0765f9f41f6d58b9e2d454ba555197be1f2e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE405 5460 bytes
font_01_sfnt_off0000f680.bin
274e099fd7b5b8aae7315c7faf0908795acb945599a9f7af7940fc6b738b3bf0
pdf-font-stream PDF embedded font (sfnt) at offset 0xF680 10476 bytes