Malicious PDF — malware analysis report

Static analysis result for SHA-256 5068d9da17a19b0f…

MALICIOUS

PDF

76.1 KB Created: 2021-03-11 18:32:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 38fa33c081c345353fae5a975bb09614 SHA-1: 2f3e782efd51b2df24bcc92cf6def01bbcc2552f SHA-256: 5068d9da17a19b0f4d5fc68a1bf4185f6dbd10d1f3d2d79f597536999aeb3200
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URI pointing to 'https://bologen.ru/wix?keyword=bousd+salary+schedule', which is likely the primary lure. The document body, though heavily obfuscated, suggests a salary schedule context, aligning with common phishing lures.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=bousd+salary+schedule
    • https://cdn-cms.f-static.net/uploads/4420910/normal_6011110f7d4e2.pdf
    • http://wutanumijejol.sportsontheweb.net/88927351526.pdf
    • http://zakewabo.scienceontheweb.net/2018_forester_review_car_and_driver.pdf
    • http://sabumow.mygamesonline.org/what_is_the_meaning_of_life_according_to_the_book_of_ecclesiastes.pdf
    • http://gatowixipeba.mywebcommunity.org/xaxukusudufuleloni.pdf
    • http://xuxetosufuzo.getenjoyment.net/descargar_audio_biblia_reina_valera_1960_mp3.pdf
    • https://cdn.sqhk.co/limizolaxa/jfTgcja/power_rangers_ninja_steel_fighting_games_download.pdf
    • https://cdn.sqhk.co/zozijawutuxu/ifoQmae/joltik_plush_pattern.pdf
    • https://cdn.sqhk.co/potiribuwuf/fFgixP1/general_knowledge_pub_quiz_multiple_choice.pdf
    • https://cdn-cms.f-static.net/uploads/4378404/normal_600cf4df44f29.pdf
    • https://cdn.sqhk.co/zezegawutogu/CvAKiir/46299611741.pdf
    • https://cdn-cms.f-static.net/uploads/4454436/normal_6037386e7b3f7.pdf
    • http://reduslimitaly-ufficiale.website/32801073288bh884.pdf
    • http://starkrobotics.org/beach_survival_island_2017_moviem9wnj.pdf
    • http://sosed.market/minizunuzovodaju7pfbu.pdf
    • https://cdn.sqhk.co/busosuwik/jUihge9/condado_vanderbilt_spa.pdf
    • http://antonioit.fun/49132293717vafzp.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c84226eb-dac5-4c55-b9d4-15f8407658a1/define_the_word_fair-minded.pdf
    • https://uploads.strikinglycdn.com/files/bec8e665-dbce-4777-841a-6be6de2331a8/pewakis.pdf
    • https://uploads.strikinglycdn.com/files/82b5f20a-2eaa-4bff-9bf4-5ee17cab00b9/the_one_kiera_cass_wikipedia.pdf
    • https://uploads.strikinglycdn.com/files/44b65249-0029-479f-9a55-b000e042415d/flowers_for_algernon_book_characters.pdf
    • https://uploads.strikinglycdn.com/files/c83af99d-b7e2-46d9-be61-6064f93a02b2/fundamentals_of_engineering_thermodynamics_9th_edition_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef58.bin
8f91f90eb8bebf4b293daa34a2fe4e67c8e8b4e2b12f548c0e7c8429cc379dc4
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF58 5180 bytes
font_01_sfnt_off000100f4.bin
9ac7ce9eebc4dc027e5acf3faa55766eee319705fa1f095123010acac5230b20
pdf-font-stream PDF embedded font (sfnt) at offset 0x100F4 10108 bytes