Malicious PDF — malware analysis report

Static analysis result for SHA-256 45bedfd916c21328…

MALICIOUS

PDF

75.5 KB Created: 2021-05-02 04:49:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a1b24691eb27ec06a1e9281ed8568a07 SHA-1: 781f39f4789b1dc0d144b6396ee4622b5a14b38a SHA-256: 45bedfd916c21328213250acf0acea8f53855c7fd01062a38f3dfce82167a702
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that, when visited, likely leads to a phishing or malware distribution site. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, appears to be related to the URL's search query, suggesting a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=maserati+granturismo+s+2008+price
    • http://kobodesuwid.getenjoyment.net/21352659231.pdf
    • http://fudipowituvu.22web.org/nefevizedofevo.pdf
    • http://1xbets-regs.site/993693694082zq0v.pdf
    • http://tamodemuror.getenjoyment.net/15806073155.pdf
    • http://tixshopclub.fun/14930767896yy65c.pdf
    • http://justiciaforjustice.com/fezabarox1b4t.pdf
    • https://cdn-cms.f-static.net/uploads/4465136/normal_6054e015d4c2b.pdf
    • https://cdn-cms.f-static.net/uploads/4485296/normal_5fe9715ca3921.pdf
    • http://lerinumemikiw.22web.org/bel_ami_historia_de_un_seductor_libro.pdf
    • http://resokipuga.getenjoyment.net/61203621219.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fidalanono.myartsonline.com/asmaul_husna_versi_nu.pdf
    • http://lamekukibudinos.epizy.com/british_medical_dictionary.pdf
    • https://3789e5f8-265e-48cd-8836-241a044b7ceb.filesusr.com/ugd/45ef7e_bdf2251eff5f426caab784391395c029.pdf?index=true
    • https://03aaa7dd-6608-466c-a68c-f41c59811c05.filesusr.com/ugd/ae15ca_c847e16c0d66408bae01750794f47e19.pdf?index=true
    • http://bumumewevebav.epizy.com/96003921894.pdf
    • https://d926c97b-7f3b-4ec8-a52a-318bcb589338.filesusr.com/ugd/120f26_5c9eb559e23346aeb949ee6f6103736e.pdf?index=true
    • http://gezibetaw.epizy.com/coolrom_ps3_android.pdf
    • http://bajupigirosinaf.atwebpages.com/9620502723.pdf
    • https://c4a0f302-b060-43a0-af10-a0364da5eca7.filesusr.com/ugd/c6d327_0359761b547f4a319f32d207dfc11952.pdf?index=true
    • https://921790ca-7b53-43bd-a25d-275d6f056404.filesusr.com/ugd/9d24cb_35fbf585d2584a5ab5188fd843bb03bf.pdf?index=true
    • https://786c536d-253b-4a15-94df-129c4693a223.filesusr.com/ugd/1fc311_503e6d532b734d94adaf5461fc49b2eb.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9c8.bin
7c48cf8e258982118cc9d52629f010815f6d467fdfcb8dd27e8feea0c428f02c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9C8 5696 bytes
font_01_sfnt_off0000fd24.bin
f6be45170d049373d911aff97d10f3d6e5620e84a888670258d9ac684c1ff1b6
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD24 10540 bytes