Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f65e5db4e914238…

MALICIOUS

PDF

91.9 KB Created: 2021-02-23 07:48:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: 9e3ec8e94c50a26e7a193ccefbb3b99f SHA-1: f487cfc20b6056db25ae5ec9e431223a456e7a85 SHA-256: 4f65e5db4e91423895150874e522e0c8d6bc20934af9cc6e62c13e321acd6bf8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI that directs the user to a suspicious domain, likely a phishing lure. ClamAV and ML classifiers also flagged this PDF as malicious, specifically identifying it as a phishing trojan. The presence of external URIs and the nature of the heuristics suggest an attempt to redirect the user to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wb?keyword=what%20is%20first%20angle%20projection PDF link annotation
    • http://thelandofbadideas.com/977007149292rie7.pdfIn PDF document text
    • http://am-sound.ru/lixinezujisawelejutiss92k.pdfIn PDF document text
    • https://gitinegu.weebly.com/uploads/1/3/4/6/134648864/c2e468b2026ace.pdfIn PDF document text
    • https://zegoliro.weebly.com/uploads/1/3/2/3/132303320/dagukakawibo.pdfIn PDF document text
    • https://jaluzirilunotu.weebly.com/uploads/1/3/2/6/132681851/vadiz-xopus.pdfIn PDF document text
    • http://hyipinvest.site/785337322695mr9v.pdfIn PDF document text
    • http://indohealth365.online/where_should_u_take_a_lost_saladozcpi.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421039/normal_5ffe6ddf4bd53.pdfIn PDF document text
    • http://kinokaiff.space/cell_wars_level_207rta9i.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475389/normal_603244e9743fe.pdfIn PDF document text
    • https://funogumoduwe.weebly.com/uploads/1/3/4/3/134309977/tosekamuxamatuw.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4379483/normal_6002d5becfd1d.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4459170/normal_5fcb9a82f1f60.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/zuguvoxoki/wofewinunupiwepisidalaver.pdfIn PDF document text
    • https://s3.amazonaws.com/pizivurapab/gidinulaluwidado.pdfIn PDF document text
    • http://zexitan.rf.gd/zulozavodadorulejuv.pdfIn PDF document text
    • https://s3.amazonaws.com/dojivewobasuval/addons_builder_for_minecraft_pe_apk.pdfIn PDF document text
    • http://lajefuvubesij.epizy.com/alternating_current_circuit_analysis.pdfIn PDF document text
    • http://nadiripu.epizy.com/schedule_template_canva.pdfIn PDF document text
    • https://s3.amazonaws.com/pilazi/welofibukutabin.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010828.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10828 5156 bytes
SHA-256: f8569bac55b1b2e2aa489f2ff4547f4ebee5b6c7f99f095ee8d0b5aa26fb67da
font_01_sfnt_off000119ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x119AE 11096 bytes
SHA-256: 22039a4bf8d92a608840ccb4431b37af3f99517f998933c14a69d9fb7ae6c814
font_02_sfnt_off00013f98.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13F98 16028 bytes
SHA-256: 3e66ce8c90719045bf8f6c8d5f716325bbce29c89c8399c9e71e7e90b46a9b16
font_03_sfnt_off000153e1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x153E1 4324 bytes
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f