Malicious PDF — malware analysis report

Static analysis result for SHA-256 4fb0b431ce0ca3a8…

MALICIOUS

PDF

81.6 KB Created: 2021-03-30 12:49:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c50cf6b7afb2f950ff2e2d50612cd986 SHA-1: 5ed15e74438208cb47566ba104467f0f03f2fc04 SHA-256: 4fb0b431ce0ca3a87e7ef686705ec5b7e4d5fa3f6b3694e86137826b03e97e94
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded URLs that lead to potentially malicious domains, as indicated by the ML classifier and ClamAV detection. The document body, though heavily obfuscated, suggests a lure related to 'Ayurvedic plants images pdf'. The presence of external URIs and the overall detection score point towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/award?keyword=ayurvedic+plants+images+pdf
    • https://static.s123-cdn-static.com/uploads/4376875/normal_6009aa33a71a5.pdf
    • http://hs-life.ru/22519791098ztuhn.pdf
    • https://kaperimivegorew.weebly.com/uploads/1/3/4/3/134371305/6b1ee613.pdf
    • http://forpost-electrica.ru/xfinity_stream_beta_app_on_roku_reviewskooi.pdf
    • https://vudizexifaret.weebly.com/uploads/1/3/4/3/134314381/49836.pdf
    • https://motutipe.weebly.com/uploads/1/3/4/6/134674000/cf619e4bf.pdf
    • http://hermidkovo.info/wasepelofukwqiaw.pdf
    • https://cdn-cms.f-static.net/uploads/4368230/normal_600a52859ed70.pdf
    • https://bifupepazabar.weebly.com/uploads/1/3/4/7/134740405/9724314.pdf
    • http://zawomuxe.iblogger.org/43160515150.pdf
    • http://pelistens.xyz/fuluzopojinil2tf3v.pdf
    • http://allwoman.site/what_manga_chapter_does_attack_on_titan_season_3_endoqcs7.pdf
    • https://cdn-cms.f-static.net/uploads/4422906/normal_6017c6e7e588f.pdf
    • https://viwomesaw.weebly.com/uploads/1/3/4/4/134472777/9346460.pdf
    • http://mebelintera.ru/fantasy_airships_steampunkcpidn.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/bupesejirijejus/60829612314.pdf
    • https://s3.amazonaws.com/fizaxo/jaguzoxuta.pdf
    • http://xasidesarilune.epizy.com/tv_stand_with_mount_walmart_canada.pdf
    • http://xevojubalane.rf.gd/who_sells_taco_bell_fire_sauce.pdf
    • http://zebigibozudival.epizy.com/reforma_antimanicomial.pdf
    • https://s3.amazonaws.com/sasufufa/how_to_start_python_on_macos.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001007e.bin
70b97a602d281028042c85001341f6a74267f7ec29e8bd200c05a553056a5151
pdf-font-stream PDF embedded font (sfnt) at offset 0x1007E 5628 bytes
font_01_sfnt_off000113ac.bin
85048456361d1b38faae7b02a50e81f0f3b47854d8ed1e1c3a8335415b9257b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x113AC 10732 bytes