Malicious PDF — malware analysis report

Static analysis result for SHA-256 404c515a7c9663f4…

MALICIOUS

PDF

68.3 KB Created: 2020-11-25 02:43:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 7af84e53317b23640945816c00320519 SHA-1: 177404b9d59dcf4a54c468d2651b33936094e41f SHA-256: 404c515a7c9663f4c0eb5b768b51ac3c7a2c79ecd23bdf4118d0463cb536ff2c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a URL that advertises a "clash of kings hack unlimited gold apk". This, combined with the ClamAV detection of Pdf.Phishing.Trojan, strongly suggests a phishing or social engineering attack aimed at tricking users into downloading potentially malicious software. No scripts were extracted, but the presence of an external URI and the phishing lure are key indicators.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafftec.ru/strik?utm_term=clash+of+kings+hack+unlimited+gold+apk PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4501208/normal_5fb928a32dff1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4376099/normal_5f8f14df5e6ff.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4373755/normal_5f8b17d2007d7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413011/normal_5f97868a4f4f2.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/dadupawo/sap_workforce_management.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8abb3c57-a31e-4af3-bb66-0f77fc8a54fb/70083884598.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6465e7c3-506b-439d-b5d0-0c3205073c69/jenakebi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e2754b4d-3c0a-4894-859a-6c737acb480d/what_is_advanced_topics_in_math.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/255a2e72-6164-4e87-93e0-f12a114cb7fd/vampire_saint_denis.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1f0f9af3-3fe2-4f9e-84e6-57cac2572587/69171299542.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cbb2473d-21da-48ed-ad2f-89419d004f15/a_giacometti_portrait.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/08626da2-31f4-42c9-bbbc-d2b35ab71f91/tujotalamilatoxesivu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ab81e640-24ee-4372-a50b-4550534f3e41/albuquerque_high_school_website.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ccce.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCCCE 5444 bytes
SHA-256: 8069eb9a4606a1233f8505b48184175a3ab55b592d393455b9645e356ae8e274
font_01_sfnt_off0000df33.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDF33 11216 bytes
SHA-256: ee3b711ae8ac42506b1bea420689356451d94e7abaa0bc581814e5d5e1b62a6c