Malicious PDF — malware analysis report

Static analysis result for SHA-256 472c43042f4edfdc…

MALICIOUS

PDF

67.4 KB Created: 2021-06-10 05:01:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 68e3efaa0e9b2b85a45de9432fdee231 SHA-1: db720c211c9b6edb386853892aeb5c23d5399b59 SHA-256: 472c43042f4edfdc465bc7abbd769ae805263d120b6c9ee169de1512055d6aa8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains an embedded URL pointing to a suspicious domain, likely intended to trick users into downloading further malware or visiting a phishing page. The document body, though heavily obfuscated, suggests a lure related to movie downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://laborke.ru/pbw?utm_term=moviesda+2019+movies+isaimini
    • https://static.s123-cdn-static-d.com/uploads/4459479/normal_60b64fcd102cc.pdf
    • https://cdn-cms.f-static.net/uploads/4465025/normal_606e250f25c53.pdf
    • https://static.s123-cdn-static.com/uploads/4414678/normal_5fcee100259ce.pdf
    • https://cdn-cms.f-static.net/uploads/4389794/normal_60338eb6bc4e3.pdf
    • https://cdn-cms.f-static.net/uploads/4447497/normal_60c15199211a2.pdf
    • https://cdn-cms.f-static.net/uploads/4493245/normal_603762fa53e06.pdf
    • https://cdn-cms.f-static.net/uploads/4381302/normal_5fdaf8de42276.pdf
    • https://cdn-cms.f-static.net/uploads/4456377/normal_604ebb98cfbbc.pdf
    • https://cdn-cms.f-static.net/uploads/4463803/normal_6055713a0b129.pdf
    • https://static.s123-cdn-static.com/uploads/4405660/normal_5ff0cde2440a1.pdf
    • https://static.s123-cdn-static.com/uploads/4450631/normal_5fe172f38e8b4.pdf
    • https://cdn-cms.f-static.net/uploads/4366319/normal_604cc0f92f34b.pdf
    • https://static.s123-cdn-static.com/uploads/4413235/normal_5ff68edf9ba93.pdf
    • https://cdn-cms.f-static.net/uploads/4416923/normal_60215fc3ba786.pdf
    • https://cdn-cms.f-static.net/uploads/4492278/normal_6028f21139022.pdf
    • https://cdn-cms.f-static.net/uploads/4413696/normal_5fdbd2a9a6133.pdf
    • https://static.s123-cdn-static.com/uploads/4469143/normal_5fed6d8b15f84.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zusemivak.pbworks.com/f/95402131623.pdf
    • https://uploads.strikinglycdn.com/files/1707bb55-cc7a-466a-bf3e-65f66c5a2f3e/88001613498.pdf
    • http://sisiwovad.pbworks.com/w/file/fetch/144959814/logowogefowede.pdf
    • https://uploads.strikinglycdn.com/files/e8255c7e-53c2-4c40-8118-4c229d917b8b/how_to_repair_polaroid_sx_70.pdf
    • https://uploads.strikinglycdn.com/files/7496ae95-5653-497f-b5d0-ddd20e6315d7/96936688200.pdf
    • https://uploads.strikinglycdn.com/files/317c7bd1-7a9e-4e1a-ad82-2bb54ad145dd/zebra_zt230_manual_calibration.pdf
    • https://uploads.strikinglycdn.com/files/b12d6196-db62-4db0-9e73-12f745124560/gajefawasew.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cc94.bin
62a9aa883c2402b304e4db41b699fb27f8aa3fa94fca9991b838498530ec68a6
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC94 5388 bytes
font_01_sfnt_off0000deed.bin
3fb11e3d50b4ba838413e46afb67d181d0ea5d0d4a83d111d37071556b749428
pdf-font-stream PDF embedded font (sfnt) at offset 0xDEED 9940 bytes