Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e87dbbd88155d36…

MALICIOUS

PDF

71.0 KB Created: 2021-05-11 21:52:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5c4924243353eff16eef847cb08746e SHA-1: d5a4fbac23cfd34c61376fa4c5eae30011d8cfad SHA-256: 4e87dbbd88155d36f4ae7801d61f01096e783b10abc3c8b4536c9869a991cbe2
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that mimics a search result for engine sales, likely intended to trick users into clicking it. ClamAV detection and ML classification strongly indicate malicious intent, specifically phishing. The presence of an external URI and the overall structure suggest this PDF is designed to redirect users to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=briggs+and+stratton+intek+engines+for+sale
    • https://cdn-cms.f-static.net/uploads/4448124/normal_604d0a36d3f41.pdf
    • https://cdn-cms.f-static.net/uploads/4489251/normal_6028f6790d398.pdf
    • https://cdn-cms.f-static.net/uploads/4378846/normal_600abef330aac.pdf
    • https://cdn-cms.f-static.net/uploads/4380210/normal_600d2dd5c0681.pdf
    • http://bella24.xyz/tawuvolavyastm.pdf
    • http://vurovolapoza.mygamesonline.org/cartesian_plane_quiz.pdf
    • https://cdn-cms.f-static.net/uploads/4414695/normal_602cf34c12d37.pdf
    • https://static.s123-cdn-static.com/uploads/4366676/normal_6005050a49a38.pdf
    • https://static.s123-cdn-static.com/uploads/4388422/normal_5fddd40d89596.pdf
    • https://static.s123-cdn-static.com/uploads/4458417/normal_5fcaf6b2e06ec.pdf
    • https://cdn-cms.f-static.net/uploads/4449627/normal_5fd68e3f63db2.pdf
    • https://cdn-cms.f-static.net/uploads/4409827/normal_600ce151de6ba.pdf
    • https://cdn-cms.f-static.net/uploads/4468836/normal_601840fe44fa7.pdf
    • http://freshka.fun/733912481924zp84.pdf
    • https://cdn-cms.f-static.net/uploads/4392861/normal_600e9c44afdf0.pdf
    • https://cdn-cms.f-static.net/uploads/4500432/normal_60676e74e5466.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://mobukug.myartsonline.com/7882124059.pdf
    • https://s3.amazonaws.com/juliziwojatige/kusinuwusadujad.pdf
    • https://s3.amazonaws.com/pewibim/nisujuvejonasirubode.pdf
    • https://s3.amazonaws.com/makixibawumebol/what_is_after_we_collided_coming_on_netflix.pdf
    • http://fabevax.myartsonline.com/worir.pdf
    • https://s3.amazonaws.com/dojivewobasuval/usmle_step_1_scores_by_school.pdf
    • http://zexaxekiki.atwebpages.com/bivariate_frequency_distribution_and_correlation_class_12.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d6fd.bin
b98b17fdf1f41c7e30b2d05efc16793f6fd1d4f76bd69821abb153eea31b786b
pdf-font-stream PDF embedded font (sfnt) at offset 0xD6FD 5188 bytes
font_01_sfnt_off0000e8ba.bin
c8813e37d9350dd394aa884d27094fddd955f44071ae1a8d02820dcb3c7a21cb
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8BA 10980 bytes