Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ff23c92ab75b080…

MALICIOUS

PDF

68.0 KB Created: 2021-02-18 12:51:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-04
MD5: c98ee4bb57dbf020c1c99dfeba1c34b5 SHA-1: 2a17e141304bd8da10c0ed1be55f78652fcde81a SHA-256: 4ff23c92ab75b080dc8a3095b9c2293154037986e2b5fd1f9118a1679ee1ae8c
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malicious redirection scheme. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, a tool sometimes used to create malicious PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=nighthawk+x4s+ac3200 PDF link annotation
    • http://easterthjg.com/36400705056rbrp8.pdfIn PDF document text
    • http://boomerangoo.site/avantree_anc031_manualrphnl.pdfIn PDF document text
    • http://lnstagramcopyrigtservice.com/is_acres_of_diamonds_a_true_storyt1q59.pdfIn PDF document text
    • http://gravkamen.ru/25425080922eogsn.pdfIn PDF document text
    • http://help-lnstagramcopyrights-verify.com/the_book_thief_study_guideks96q.pdfIn PDF document text
    • http://steelsho3.club/skater_xl_multiplayer_2020bq9pw.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4409118/normal_5fd91f1ae6928.pdfIn PDF document text
    • http://rubisteq.online/how_to_start_a_music_business_onlineivehi.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4401703/normal_600fee050e789.pdfIn PDF document text
    • http://blankid.ru/1512918984674lqo.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412377/normal_60204466231f1.pdfIn PDF document text
    • http://svarka-aurora.online/billboard_top_100_year_end_2017vfctr.pdfIn PDF document text
    • http://qqkaxes.xyz/sapphire_plugin_serial_numberk6j84.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jasadavebaga/fikevugimukadefaj.pdfIn PDF document text
    • https://s3.amazonaws.com/piwupevivotixi/vsco_cam_apk_todos_los_filtros_2019.pdfIn PDF document text
    • https://s3.amazonaws.com/zozofufulolig/58951250028.pdfIn PDF document text
    • https://s3.amazonaws.com/vidadaviwal/xazerojikep.pdfIn PDF document text
    • https://s3.amazonaws.com/muvemasoxaji/22213369453.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cb41.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCB41 5652 bytes
SHA-256: cdf83dec430321508581a8fc659993f0b4bd73c9f0da71f1bd7f6f6a63c9ee6d
font_01_sfnt_off0000dea8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDEA8 10640 bytes
SHA-256: eba8b12886e193ec8ca0f8373b352004c31213c5e9e05deaac4c5ecf644fe5cd