Malicious PDF — malware analysis report

Static analysis result for SHA-256 476e8a993540275d…

MALICIOUS

PDF

80.2 KB Created: 2021-06-01 02:24:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ba5d897ce8879b0c97bbe76fa1679f81 SHA-1: ec1e335050210a16f2bb9314d0e31fc4b241cee4 SHA-256: 476e8a993540275d2d2dca44c9b8b2ec44f7a2c5363a819c4995e9ba5e224943
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. The embedded URL and the document's content suggest a lure related to 'Minecraft pocket edition for pc windows 7' to trick users into downloading a payload. The presence of PDF_URI and EMBEDDED_URL heuristics further supports this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://irlanc.ru/pbw?utm_term=minecraft+pocket+edition+for+pc+windows+7
    • https://cdn-cms.f-static.net/uploads/4486054/normal_604f09e90d2e9.pdf
    • https://cdn-cms.f-static.net/uploads/4493873/normal_600e058ab6467.pdf
    • https://cdn-cms.f-static.net/uploads/4417990/normal_606d57f35874c.pdf
    • https://cdn-cms.f-static.net/uploads/4417207/normal_606df5d1771b8.pdf
    • https://cdn-cms.f-static.net/uploads/4371272/normal_60332029b675b.pdf
    • https://cdn-cms.f-static.net/uploads/4368500/normal_605f405933298.pdf
    • https://static.s123-cdn-static.com/uploads/4370066/normal_5ff273219b3a8.pdf
    • https://cdn-cms.f-static.net/uploads/4491175/normal_604492b860b5d.pdf
    • https://cdn-cms.f-static.net/uploads/4428341/normal_600f96eb3d508.pdf
    • https://static.s123-cdn-static.com/uploads/4408319/normal_5fed61f7db305.pdf
    • https://cdn-cms.f-static.net/uploads/4475580/normal_5fdbd9cc00d36.pdf
    • https://static.s123-cdn-static.com/uploads/4482636/normal_6001d879ca33f.pdf
    • https://cdn-cms.f-static.net/uploads/4484633/normal_6017c635f3d0e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://noxixap.pbworks.com/w/file/fetch/144426375/pdf_calendario_2020_mexico_para_imprimir_gratis_chile.pdf
    • https://uploads.strikinglycdn.com/files/df6779f7-a5cd-47c3-8761-4d24a5d5605c/rajigilitoxatowidepumepo.pdf
    • https://uploads.strikinglycdn.com/files/d7f51658-4efe-4129-97c5-254558fab9e6/rca_3_device_universal_remote_codes_for_roku.pdf
    • https://uploads.strikinglycdn.com/files/105f1b4c-47bf-463b-a177-45ab3b2da735/vipiberugativabuniwujeb.pdf
    • https://uploads.strikinglycdn.com/files/ed2eb99d-05b4-4e64-b2fd-4e4144d04c68/94263562135.pdf
    • http://zikupuzajix.pbworks.com/f/zubixumurugap.pdf
    • http://tazijebep.pbworks.com/f/farmhouse_coffee_table_plans_free.pdf
    • http://supatibu.pbworks.com/f/hungry_dragon_hack_apk_1._11.5.pdf
    • https://uploads.strikinglycdn.com/files/a656c3d2-3481-466e-a4f4-b91193f599aa/8973504513.pdf
    • https://uploads.strikinglycdn.com/files/cc4041ff-cac9-42df-80a9-50c2711e7208/venn_diagram_examples_3_circles.pdf
    • https://uploads.strikinglycdn.com/files/fa486920-c67b-4362-a1e7-a33f2df63897/kokolikoko_sopa_de_letras_respuestas.pdf
    • http://tisowowuduwe.pbworks.com/w/file/fetch/144417753/3787194316.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebc4.bin
db4dc6e9c48dacde50d508640f9fe968512be306b9a3587a97ff069efba59935
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBC4 5148 bytes
font_01_sfnt_off0000fd67.bin
ae3508ae8520d9ef78062ad4029a0b0f65a14b61a2e87aec76ab4391bc01defd
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD67 12212 bytes
font_02_sfnt_off000124c9.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x124C9 4324 bytes