Malicious PDF — malware analysis report

Static analysis result for SHA-256 4787dbc9842af6af…

MALICIOUS

PDF

91.7 KB Created: 2021-03-28 05:46:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 7ef9f50a1a1410bb2236225b0889d2e5 SHA-1: 68671800f366227da20484b7a899cc279586a0dd SHA-256: 4787dbc9842af6af73cbd09ff23807b6c57607e7239e408579ff9bb2fd2b9076
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains embedded URLs, one of which, 'https://jumiwimov.ru/award?keyword=advanced+excel+full+course+pdf', is presented as a lure for an 'advanced excel full course pdf'. The presence of a 'SE_LOLBIN_RUN_COMMAND' heuristic suggests potential execution of commands, possibly involving PowerShell, to download and execute further stages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=advanced+excel+full+course+pdf PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4457563/normal_5fc61043cfe51.pdfIn PDF document text
    • http://hightrade.club/70579266949nzbgu.pdfIn PDF document text
    • http://nosinoski.shop/sofewumezagadelipijugs08g.pdfIn PDF document text
    • http://garderob-podolsk.ru/kotabulogixiruriledo46vki.pdfIn PDF document text
    • http://bt-management.website/warranty_deed_wisconsin_formmtkim.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369763/normal_604b2fe82987f.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4473388/normal_5fe0e9965eb51.pdfIn PDF document text
    • http://shopbest.online/windows_powershell_5.0_free_download8avpd.pdfIn PDF document text
    • http://gouliwer.online/kurumefodurizowl4vf1.pdfIn PDF document text
    • http://ita-talia.fun/cs_1.6_cd_key_code624aw.pdfIn PDF document text
    • http://agencymedia-ig.com/mp_board_10th_class_maths_book_solutl6031.pdfIn PDF document text
    • http://gouliwer.onlineIn macro / runtime command snippet
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/0de83207-dced-4f04-8029-25afa2297516/rigging_your_fly_rod.pdfIn PDF document text
    • https://d525ee04-2a40-494f-8ba9-fee52f7b18ee.filesusr.com/ugd/8b8e24_f977dadfd562425f8ff45cb99cc55f4f.pdf?index=trueIn PDF document text
    • https://29aa9d28-cc9d-45fc-8d86-3718b5881c84.filesusr.com/ugd/74c34a_d341af7ca7544ee4a028a71c062d5d71.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/44f85c16-9000-4b6b-ba34-01bd5ff4acdc/high_chair_weight_capacity.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/730c5f95-be91-4141-9606-2a335b725da1/74282237237.pdfIn PDF document text
    • https://s3.amazonaws.com/jaloto/ischemic_stroke_guidelines_2018.pdfIn PDF document text
    • https://s3.amazonaws.com/daraniwekamidir/mezegenidukegoranewagif.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/439aed4d-6533-4fff-9f4a-c195b9639d1b/vasil.pdfIn PDF document text
    • https://s3.amazonaws.com/nuvukivaxiren/aashiqui_2_naa_songs_telugu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dceee48d-fd75-4d51-9dec-d8739faa31e5/24881097253.pdfIn PDF document text
    • https://34e51215-b586-4e01-b3ea-a219475a7b91.filesusr.com/ugd/46481b_f1b3a01fcb524a0c92af4477d3b62b04.pdf?index=trueIn PDF document text
    • https://1cdd1dcb-54a5-4750-95ad-c4cce9a68cd1.filesusr.com/ugd/1e32c2_05ff1980b5d34e71b0fe18105a0944e8.pdf?index=trueIn macro / runtime command snippet
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000113ef.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x113EF 5268 bytes
SHA-256: 14550d80c84268a38d42410381f864d8f81a30140e7a0887f68d8babb48e8fbf
font_01_sfnt_off000125f9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x125F9 11280 bytes
SHA-256: 8bdf16f19af8a949711a74c40698aeca51c1d19c24a302c3b941ccdc65260f5d
font_02_sfnt_off00014cb5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14CB5 16036 bytes
SHA-256: 354dce64f07f3d7acdf6a04edf763950ffbfec4edcbb4bfe17b65a83544077bb