Malicious PDF — malware analysis report

Static analysis result for SHA-256 4694ae13c9be8a2a…

MALICIOUS

PDF

77.5 KB Created: 2021-06-01 10:29:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 80767cf4a52d498d9dd5dfd184afc40e SHA-1: e329ae562234eb55a43d99a53b982fa64bdaf6e2 SHA-256: 4694ae13c9be8a2ac18fdc5d581e5916d197defed979e169fc4ba85dd5414519
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URI pointing to 'https://ketchas.ru/pbw?utm_term=vedic+maths+pdf+free+download+in+marathi', which is likely the malicious payload or phishing site. The document body, though heavily obfuscated, suggests a lure related to 'Vedic maths pdf free download in marathi'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7309

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ketchas.ru/pbw?utm_term=vedic+maths+pdf+free+download+in+marathi
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/8926415c-3cf7-45b8-b5b7-cef30546dbbe/bissell_spotbot_pet_33n8_manual.pdf
    • https://uploads.strikinglycdn.com/files/c046d8d5-5050-4279-bf4b-bc776364a106/ejercicios_resueltos_de_balances_activo_pasivo_y_patrimonio_neto.pdf
    • https://uploads.strikinglycdn.com/files/ef50c2a3-cc1a-455e-8955-682ef57f7f26/navy_eval_input_form.pdf
    • https://uploads.strikinglycdn.com/files/2e3d4b85-d74f-4418-9195-e25c8fdc2d7d/northeastern_university_academic_calendar_2015-16.pdf
    • https://uploads.strikinglycdn.com/files/bef0be7a-4185-4384-8522-3bef68781e52/84250273856.pdf
    • https://uploads.strikinglycdn.com/files/3005103c-c33f-4089-949c-79f23e11ae02/kivawusenotun.pdf
    • http://sorawako.pbworks.com/f/conjuguemos_preterite_vs_imperfect_5_answers.pdf
    • http://nusuwoxub.pbworks.com/f/windows_loader_2.2_2_by_daz_activator_windows_7_free_download.pdf
    • https://uploads.strikinglycdn.com/files/547f27cc-0c1f-46e1-9162-d31797d2e229/75478012371.pdf
    • http://vibevekofano.pbworks.com/w/file/fetch/144426585/shapes_worksheets_for_preschool.pdf
    • https://uploads.strikinglycdn.com/files/553f44be-7dd5-4368-8807-9e25c4573062/52689852849.pdf
    • http://tagexoba.pbworks.com/w/file/fetch/144422664/gozivix.pdf
    • https://uploads.strikinglycdn.com/files/7ea16fb9-dffd-4fd2-b801-c090bfd54115/rufugeposituxisobusezono.pdf
    • https://uploads.strikinglycdn.com/files/e67925ad-dee4-4f28-8237-cb63583ced5e/descripcion_de_los_personajes_del_libro_el_amor_en_los_tiempos_del_colera.pdf
    • https://uploads.strikinglycdn.com/files/7de05912-0f32-4ff7-8111-6408367d44d2/que_es_un_oso_panda_grande.pdf
    • https://uploads.strikinglycdn.com/files/345f6fc6-0e4a-4d63-988f-67d9ccbff597/what_size_bobbin_for_singer_4411.pdf
    • https://uploads.strikinglycdn.com/files/c33e0bf2-85de-4445-bd56-d2d9d169a1de/interrogative_pronouns_worksheet_grade_10.pdf
    • https://uploads.strikinglycdn.com/files/b73816f1-fb0b-4e3b-9e65-68ebf0d6ca96/24713477740.pdf
    • http://wuvebag.pbworks.com/w/file/fetch/144428778/solving_systems_of_equations_by_graphing_worksheet_answer_key_kuta_software.pdf
    • https://uploads.strikinglycdn.com/files/2fc7cced-8138-4eb3-b378-402f2a8efcac/what_is_the_punishment_in_the_7th_circle_of_hell.pdf
    • https://uploads.strikinglycdn.com/files/7383d73e-d36f-4473-ab19-5aaa6d7cf1b1/how_to_relieve_back_pain_when_pregnant.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5b4.bin
138f9912586df256a75159556a74aad20f20ecdf1b51d7ff359c5c26481201fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5B4 3064 bytes
font_01_sfnt_off000100aa.bin
b53f36f7dd0b0eb21ffbbc7457a01a698257bb53c571dc5b8e6e9ec03c701b2c
pdf-font-stream PDF embedded font (sfnt) at offset 0x100AA 5452 bytes
font_02_sfnt_off0001131e.bin
7bfefc985d142a43cff786090175a73d6eb76589d81be2f2206b97d57202bfbe
pdf-font-stream PDF embedded font (sfnt) at offset 0x1131E 12160 bytes