Malicious PDF — malware analysis report

Static analysis result for SHA-256 476a39c3d37fed43…

MALICIOUS

PDF

80.8 KB Created: 2021-03-18 16:25:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: 5b794cbb271b05a9117ee627c8363535 SHA-1: b0dc6a16dc19324a61f6f58ae01a48873f9682ba SHA-256: 476a39c3d37fed43fda04ade2242d04c08d9fa6e63b2007a3d59864137f7a647
116 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains heuristics indicating it is malformed and contains an external URI. The ML classifier and ClamAV detection strongly suggest malicious intent. The embedded URL points to a domain associated with phishing, likely attempting to deliver a malicious payload or redirect the user to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=authorized+signature+letter+pdf PDF link annotation
    • http://arm-watch3.club/bonumefuwixujamixuk9izj0.pdfIn PDF document text
    • http://momentikshop.space/5680588021humax.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419846/normal_600e37a6bf0ad.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4450517/normal_5fcbdf4510429.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4473322/normal_601aaa49489cc.pdfIn PDF document text
    • http://creditscorefix.info/405588068545snq5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408862/normal_6051b55920e3f.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470679/normal_6008dfa0a8e5d.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/bd2986e6-a66a-48f4-8f9f-581d48948580/very_short_scary_stories_for_middle_school.pdfIn PDF document text
    • https://s3.amazonaws.com/zoromexemuzid/panasonic_rice_cooker__multi-cooker_sr-g06fgl_3-cup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/47d70cd9-5aa9-4ca7-83d0-2c7d47d94a0f/46590913863.pdfIn PDF document text
    • https://s3.amazonaws.com/lofese/labokokuwa.pdfIn PDF document text
    • https://s3.amazonaws.com/tugumeb/which_english_accent_is_most_attractive.pdfIn PDF document text
    • https://s3.amazonaws.com/befarekogol/apex_dt502_digital_tv_converter_remote_control_code.pdfIn PDF document text
    • https://s3.amazonaws.com/meludav/21504314961.pdfIn PDF document text
    • https://s3.amazonaws.com/tufitijinexu/best_bitcoin_miner_android_2019.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3abbc4ca-393b-45da-8522-87e1c885570f/nixamemafuz.pdfIn PDF document text
    • https://s3.amazonaws.com/sorogamat/9915980825.pdfIn PDF document text
    • https://s3.amazonaws.com/gidibesuxi/rutelajajebeboxo.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fefc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFEFC 5344 bytes
SHA-256: de9d44a1e0c4011c7c91346336ce4db3d381a9fca8d261bd4aaa78a469e9c0d5
font_01_sfnt_off0001112b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1112B 10796 bytes
SHA-256: bbb67e871b68bcdf5e1195cd160284d9eb905796235ba7a21d705a44a8e5e5e0