Malicious PDF — malware analysis report

Static analysis result for SHA-256 40c1ca695df6fa99…

MALICIOUS

PDF

74.4 KB Created: 2021-03-23 22:17:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c8a0a79196e09c02489304278908da2d SHA-1: d8ea6d855c8f25ce5276b25fa607e52be8646fa7 SHA-256: 40c1ca695df6fa994070fb0493e66524492f3496db09c02fd9ff50ebde3c9365
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating an external URI and is flagged by a machine learning classifier and ClamAV as malicious. The embedded URL 'https://soxebez.ru/wix?keyword=april+fools+worksheets' is likely used to redirect the user to a phishing or malware distribution site. The document body, though heavily obfuscated, contains text related to 'April fools worksheets', suggesting a social engineering lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=april+fools+worksheets
    • https://cdn-cms.f-static.net/uploads/4479451/normal_602d8033185d3.pdf
    • http://batmbatm.ru/saxajegixi3sao4.pdf
    • https://cdn-cms.f-static.net/uploads/4373243/normal_6052d2a377ac5.pdf
    • https://rijagadufe.weebly.com/uploads/1/3/1/6/131606992/mabiwoveva.pdf
    • https://gitodaxip.weebly.com/uploads/1/3/5/9/135960033/5383338.pdf
    • http://gerda-msk.ru/474764057113lhij.pdf
    • https://gidipefodato.weebly.com/uploads/1/3/5/3/135348522/3073032.pdf
    • https://cdn-cms.f-static.net/uploads/4382627/normal_6035a282338ad.pdf
    • http://bathforlegs.xyz/spotlight_room_escape_level_1_afterlightitoxp.pdf
    • https://static.s123-cdn-static.com/uploads/4482858/normal_5fcc1f3dbac2a.pdf
    • http://cadenalia.com/49581667686il69d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fajeloninesitel/23994439959.pdf
    • https://7211abc3-b26e-437e-abd8-8a8c7ebd4af5.filesusr.com/ugd/0683fb_8b78668cb1ec49fab711984bdba15dce.pdf?index=true
    • https://ba3a7bb5-edd2-4228-b29c-cf272df6a868.filesusr.com/ugd/bd1c09_24d5f4c731a44d998e0cfef33dbd8906.pdf?index=true
    • https://s3.amazonaws.com/jagux/best_romance_novels_for_12_year_olds.pdf
    • http://mebexadesojixip.rf.gd/56404973298.pdf
    • http://navibizo.rf.gd/fdic_call_report_information.pdf
    • https://s3.amazonaws.com/nufidibodudulad/full_size_bed_sheet_dimensions_in_inches.pdf
    • https://s3.amazonaws.com/vavale/lepovuwilurirezata.pdf
    • http://tuzawuza.epizy.com/pepugigojibimajafo.pdf
    • https://s3.amazonaws.com/wozowuledij/25968218583.pdf
    • https://5457524e-bace-410a-9ce7-c8d8bc0eedea.filesusr.com/ugd/f0ffd0_700a784c2eb04cf2bf8d0cd4a2eb1190.pdf?index=true
    • https://bee08bb6-d8c1-4cc5-89f0-d6ac88a4f64a.filesusr.com/ugd/8b8a1f_84255a8618204b9b8bbffba649bdce77.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4d5.bin
3784aec7be16fc78512048f90e391cee7d5dadd8d2af15730f70def6123255da
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4D5 4924 bytes
font_01_sfnt_off0000f5ab.bin
16f6e3dadda7e3682e49b051af6636893bdc355cc171e91c3f1a10b08a4b07d4
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5AB 11020 bytes