Malicious PDF — malware analysis report

Static analysis result for SHA-256 4267d8864d1c87fb…

MALICIOUS

PDF

79.2 KB Created: 2021-06-02 12:15:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8507bcd9b3a08124e1312051176bb5e0 SHA-1: 231c97027a4944dc7d0845fc8de83d611ed18021 SHA-256: 4267d8864d1c87fb975e7ebb7ab99e75c96be5326c4d4cea8ebee6d149a8e626
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded JavaScript, a common technique for exploiting PDF viewers or redirecting users to malicious sites. The ML classifier and ClamAV detection strongly indicate malicious intent. The embedded JavaScript likely attempts to download and execute a second-stage payload from one of the numerous unknown URLs found within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://getawaynewzealand.co.nz/wp-content/plugins/formcraft/file-upload/server/content/files/16070f329ac470---vipesupurekal.pdf
    • http://irina-beha.com/ckfinder/userfiles/files/38125886343.pdf
    • https://globalclassic.org/wp-content/plugins/super-forms/uploads/php/files/ouhg09n2bisj7i3a6ck9orhrbj/zinubolujizaraxev.pdf
    • http://www.lightingandhvacexpo.com/wp-content/plugins/super-forms/uploads/php/files/3865140b5e145b72df5b7f37964d96b1/keletusopuwabevekebipa.pdf
    • http://christembassydocklands.org/wp-content/plugins/super-forms/uploads/php/files/c88f847006c7ea526ff46d7752098b36/jenobamawipekusipijimir.pdf
    • http://dynamic1984.com/user_file/file/tevukixerivupa.pdf
    • https://www.hediyevideo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a52ea8cb3af---lesamenufekelez.pdf
    • https://readxyz.com/wp-content/plugins/super-forms/uploads/php/files/0322923a1ee885495ff86b242e0dcfde/wopagiwoworo.pdf
    • https://bawwabatrizq.com/userfiles/file/pofudoso.pdf
    • http://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/jonvnfbp47l4au4r1d955vd432/1189545309.pdf
    • http://alliusie.com/userfiles/file/3917967619.pdf
    • http://www.morenoroofing.com/wp-content/plugins/formcraft/file-upload/server/content/files/160727ff33e0b6---fisavogowozepasobageb.pdf
    • https://nowackleverkusen.de/wp-content/plugins/formcraft/file-upload/server/content/files/16080c26194ea5---37770788349.pdf
    • https://skyfireconsulting.com/wp-content/plugins/super-forms/uploads/php/files/gc68e2amuiut36l58k5fgl6hkr/mafojokaw.pdf
    • https://adiwirawanbali.com/wp-content/plugins/super-forms/uploads/php/files/8cde027617ca3a482e885c86bfa909e7/nibujaterifu.pdf
    • http://lordbeaverbrook1973.com/clients/76835/File/42781489175.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/fzgW7-mxBc0/uplcv?utm_term=operaciones+con+porcentajes+ejercicios+resueltos+pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00011131.bin
1065b351fe40c0fd6f6503a1ca012bc17243fe1dc345b36bbb413d5d38afc71f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11131 18168 bytes
font_00_sfnt_off0000d78e.bin
de05deb17f7aeb6c22cc39446bc00767611e4e8657be5ffe069b216ecd144a7f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD78E 5252 bytes
font_01_sfnt_off0000e976.bin
cc4f6edcc67a68540bc4eb941dd4c24884a8d37a579cb54142a38442c8655dee
pdf-font-stream PDF embedded font (sfnt) at offset 0xE976 12224 bytes