Malicious PDF — malware analysis report

Static analysis result for SHA-256 4265a0db13b16be9…

MALICIOUS

PDF

79.9 KB Created: 2021-06-02 02:30:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c0af16298b5efc06a3978a75096f0163 SHA-1: d6f218f508be71179bf18524eed1628af696423c SHA-256: 4265a0db13b16be9c752efc72003c04011965b64707eaa1c96d30512d5746cd4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains an embedded URI pointing to 'https://allytemp.ru/pbw?utm_term=macbeth+act+2+discussion+questions+answers', which is likely part of a phishing lure. The document body, though heavily obfuscated, suggests a pretext related to 'Macbeth act 2 discussion questions answers' to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://allytemp.ru/pbw?utm_term=macbeth+act+2+discussion+questions+answers
    • https://zezowamizafomex.weebly.com/uploads/1/3/1/3/131381240/dinojuwosuxegup-pikideduluwo-sevabogedutel.pdf
    • https://wivixovipi.weebly.com/uploads/1/3/4/4/134442696/6a0cdea2f.pdf
    • https://kiwotatuna.weebly.com/uploads/1/3/1/8/131856308/3619092.pdf
    • https://wekegakusujesal.weebly.com/uploads/1/3/4/2/134266445/lowedu.pdf
    • https://xuzojawuwakobo.weebly.com/uploads/1/3/4/3/134312069/2131085.pdf
    • https://kelukija.weebly.com/uploads/1/3/4/3/134337818/30a3d4ee077210.pdf
    • https://bogobesupagal.weebly.com/uploads/1/3/0/7/130775478/1092127.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://banusiv.pbworks.com/w/file/fetch/144481152/70349864700.pdf
    • http://mogulazedub.pbworks.com/w/file/fetch/144482622/jixepofotabitoxebivefo.pdf
    • http://pamotekegopa.pbworks.com/f/zaborakukolus.pdf
    • http://mujusevo.pbworks.com/f/what_is_the_current_level_of_unemployment_in_nigeria.pdf
    • http://nusuwoxub.pbworks.com/f/4126878863.pdf
    • https://uploads.strikinglycdn.com/files/331c3e26-5152-4cc3-8d53-90d8afddc36c/siemens_plc_tutorial.pdf
    • http://sozakuvepar.pbworks.com/w/file/fetch/144483294/how_much_space_do_you_leave_when_parallel_parking.pdf
    • https://uploads.strikinglycdn.com/files/0631a2ed-5abc-4670-9da2-b9f318de1e50/do_androids_dream_of_electric_sheep_summary_chapter_5.pdf
    • http://sipibujewadu.pbworks.com/w/file/fetch/144482673/eitici_ouk_oyunlar_bedava_oyna.pdf
    • https://uploads.strikinglycdn.com/files/6aef1abe-6249-4ee4-8e74-2776918b8214/what_are_the_most_important_quotes_in_macbeth.pdf
    • https://uploads.strikinglycdn.com/files/3c8ee561-a0d4-4ddd-ac6c-3ab71e9a1a50/arunachalam_1997_tamil_full_movie_download_tamilrockers.pdf
    • http://mogulazedub.pbworks.com/w/file/fetch/144483048/navpers_1306_7_guide.pdf
    • http://zopujoxobug.pbworks.com/w/file/fetch/144419379/dapaxave.pdf
    • http://jutifakukap.pbworks.com/w/file/fetch/144482568/how_to_play_ticket_to_ride_online_with_family.pdf
    • http://lekuzax.pbworks.com/f/ejercicios_de_matematicas_para_segundo_grado_de_secundaria_resueltos.pdf
    • https://uploads.strikinglycdn.com/files/3af005b8-86bc-4a3c-9d5b-1f44cd52efb0/55542674870.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec9a.bin
489eef418cf7c0655f36462b9f4e770718e7c4fa25f0b39ed8e364da7aa37579
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC9A 5372 bytes
font_01_sfnt_off0000fedc.bin
65f364eb4eac07049f70cb134adbf84ef9092c703c67fa3796e78b5e718b2a62
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEDC 11000 bytes
font_02_sfnt_off000123be.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x123BE 4324 bytes