Malicious PDF — malware analysis report

Static analysis result for SHA-256 4bbf790c99cb6b3e…

MALICIOUS

PDF

192.0 KB Created: 2021-02-03 03:14:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-17
MD5: 0740f266cb2c08fcf66d98631c229de7 SHA-1: 7fab94fb7b127259b4544bc755bd7934b2d84d8a SHA-256: 4bbf790c99cb6b3e87769c6033ad6c3dd3ebbd97cab38b97a9714a357a016843
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing or trojan threat. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a malicious site. The document body, though heavily obfuscated, suggests a lure related to an IKEA product, aiming to trick users into clicking the link. No scripts were extracted, but the presence of external URIs and the overall detection profile strongly suggest a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9682

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/123?utm_term=folding+laptop+table+ikea PDF link annotation
    • http://menetufebev.22web.org/rowajurezasenasidepu.pdfIn PDF document text
    • https://cdn.sqhk.co/pevizopubok/ygh0Dgf/xebuzepukagizadudazadofi.pdfIn PDF document text
    • http://vusejulene.iblogger.org/bugasasiret.pdfIn PDF document text
    • https://cdn.sqhk.co/sufokorume/tkYgjJc/photo_collage_maker_software_for_windows_7.pdfIn PDF document text
    • https://cdn.sqhk.co/jabosuve/fIJ6hdE/jogirurufimitanodow.pdfIn PDF document text
    • https://cdn.sqhk.co/wuvotalek/jahhDDS/train_controller_salary_nz.pdfIn PDF document text
    • https://cdn.sqhk.co/belexewuwif/iigfzgf/big_win_hockey_download_pc.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zonivezada/guide_du_routard_cambodge_laos.pdfIn PDF document text
    • http://joxepivebafugig.epizy.com/3219053116.pdfIn PDF document text
    • http://lulojoduvos.epizy.com/beko_cfp1691w_fridge_freezer_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/bisute/spotify_web_player_songs.pdfIn PDF document text
    • https://s3.amazonaws.com/xidazeze/fitted_crib_sheet_pattern_free.pdfIn PDF document text
    • https://s3.amazonaws.com/divexikav/82766210362.pdfIn PDF document text
    • https://s3.amazonaws.com/zobuwubedak/43261176774.pdfIn PDF document text
    • https://s3.amazonaws.com/lazolu/7615365937.pdfIn PDF document text
    • https://s3.amazonaws.com/forupokisip/arquitectura_sostenible_lexus.pdfIn PDF document text
    • http://wopapaxepesibad.epizy.com/run_android_apps_on_pc_bluestacks.pdfIn PDF document text
    • https://s3.amazonaws.com/zevutebulaworel/react_native_android_emulator_network_error.pdfIn PDF document text
    • https://s3.amazonaws.com/wekibik/chronic_uti_treatment_guidelines.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_010_off0002dfaa.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2DFAA 6504 bytes
SHA-256: 4580020df3eb604dc51445abf3b827d85572ebd65afab3e1f1c566e70720a5ae
font_00_sfnt_off00025ee3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x25EE3 7516 bytes
SHA-256: 075fb9e944568478c94e38805233b1125798969703103af32602e568e806d8e3
font_01_sfnt_off0002729a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2729A 5012 bytes
SHA-256: d153a23356366a50383311900ae44a72ae9126b93892dd38820bd36f8c0ce573
font_02_sfnt_off00028379.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x28379 6280 bytes
SHA-256: 9b26e63dddb061148d2096f8a3abd9ddbfbe7663dcfe2e6edc24d1b84c1ba01d
font_03_sfnt_off000292e3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x292E3 18500 bytes
SHA-256: 8a55784c5c189d74f8dc56992e1a814c31379182c6155942de0bb7dd863d9e78
font_04_sfnt_off0002c90c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2C90C 16516 bytes
SHA-256: 04fe25b29f051d70f1708f46f478918d30a58f8dd56488b8fb7dbeafae74b6e1