Malicious PDF — malware analysis report

Static analysis result for SHA-256 3afa92c15b02ab3a…

MALICIOUS

PDF

95.8 KB Created: 2021-04-04 19:41:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: d58682de945a7683c94d732bd8f9d149 SHA-1: 054c2f21dd3ab1679315deae840bbdba342a997c SHA-256: 3afa92c15b02ab3a7fde5930304ee0558da63e1536e2240f28b354c7df1feeda
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, with heuristics indicating the presence of external URIs. The document body, though partially corrupted, suggests a lure related to an 'IPL 2020 schedule player list pdf'. The embedded URLs likely lead to further malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/award?keyword=ipl+2020+schedule+player+list+pdf PDF link annotation
    • https://cdn.sqhk.co/xubodijixali/eidhgtC/nozagiwixopod.pdfIn PDF document text
    • https://cdn.sqhk.co/gozigawefo/hfigibT/wototesukedajigategilo.pdfIn PDF document text
    • https://cdn.sqhk.co/rumobotituda/8iejhhh/risitawapabosuxa.pdfIn PDF document text
    • https://cdn.sqhk.co/jukunobegabe/bw1ijjh/sherwin_williams_colorsnap_visualizer_for_iphone.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4392463/normal_5ffdc664340d7.pdfIn PDF document text
    • https://cdn.sqhk.co/kamavedes/dPEfXjd/kisekoluxediwe.pdfIn PDF document text
    • http://amandeepsadyora.com/mefezokekibigimedetelbyq7m.pdfIn PDF document text
    • http://iuts.space/24018062065j6i6a.pdfIn PDF document text
    • http://medtechnika1.ru/343379925387txcx.pdfIn PDF document text
    • https://cdn.sqhk.co/vopofuxo/iegg0oX/tibemerileraniroj.pdfIn PDF document text
    • https://cdn.sqhk.co/napumefu/hi2UCij/go_planet_captain_planet.pdfIn PDF document text
    • https://cdn.sqhk.co/vedanoderifu/jijjjgj/hitman_2_sniper_assassin_challenges_got_a_light.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4451750/normal_5fc993f82ca40.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/sikuva/fonofatewetutidu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b1c32556-523e-49e5-b6d8-cdc643ba9dd9/28032653153.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3cdc7fc7-b23b-41c2-8795-4931fc4c86fa/8620_missing_or_failed_printhead.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f64d249-2f90-4ebe-a620-f0b417df620c/how_to_fix_roomba.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4b0e8d07-1c61-4b2e-a0b5-46092d867af3/volume_formula_for_right_triangular_prism.pdfIn PDF document text
    • https://s3.amazonaws.com/kagedatabujo/sugar_candy_manufacturing_process.pdfIn PDF document text
    • https://s3.amazonaws.com/bopuxosavubare/56202482202.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36fbab50-eaa0-4909-870a-745cfb3ccdb1/which_beretta_is_made_in_italy.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103bd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x103BD 6744 bytes
SHA-256: 048fb1891f432488516cd811e7b04d68e7d39e548ca3495625137f8fb0c23ff4
font_01_sfnt_off000114a2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x114A2 5556 bytes
SHA-256: 95774d1ef5ed5b650e44c493998ce32f160613a8baddeac7f181342e2ead2d71
font_02_sfnt_off00012785.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12785 3756 bytes
SHA-256: dd2cfa85142f583a5c7faffca55174615ba4cd6ed38714e58e688cff300a15a6
font_03_sfnt_off0001366f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1366F 11008 bytes
SHA-256: fa0f7f53ad8c9e3e319f39a2248b89b5b1e7d68c1e2232287c39f21858e4319f
font_04_sfnt_off00015c1a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15C1A 16036 bytes
SHA-256: 9559dd1bd908241551916101fda3d445a26f5c4b506a1423f23393456f9d5940