Malicious PDF — malware analysis report

Static analysis result for SHA-256 523a2ed1bb36985e…

MALICIOUS

PDF

78.2 KB Created: 2021-03-30 09:54:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bf3a1827662c27cbfb6a41b144d5293e SHA-1: 92ae22625f1a6c73d6b5dcdef1799cb67c48beb9 SHA-256: 523a2ed1bb36985ee546b15004c0a2adf0ed65c40f4d05be8b35749082297fbb
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://ponafet.ru/wix?keyword=turnback+cave+guide', which is likely part of a phishing or malware distribution scheme. The presence of multiple suspicious URLs further supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=turnback+cave+guide
    • http://totalcreditreport.info/aloha_pos_manual_2018ks0n9.pdf
    • http://damvglaz0.xyz/pali_canon_meaning_in_englishyqjez.pdf
    • https://cdn-cms.f-static.net/uploads/4403817/normal_60494dbb987dd.pdf
    • https://cdn-cms.f-static.net/uploads/4500692/normal_6059606a5147d.pdf
    • http://gachihyper.xyz/the_way_of_the_masterzv3sl.pdf
    • http://eurofamily.pro/uc_browser_apk_old_version_2020y4rzk.pdf
    • http://voicebftyi.com/how_do_i_love_thee_theme0ju69.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/809e500b-6fdf-421b-a641-fce388d4bc5a/76159734333.pdf
    • https://s3.amazonaws.com/muxegeza/california_association_of_realtors_application_to_rent_screening_fee_revised_12_19.pdf
    • https://s3.amazonaws.com/fonazuzixagizir/firefox_offline_installer_xp.pdf
    • https://uploads.strikinglycdn.com/files/7442d7b9-f79f-4641-864e-2c0e84d03bc6/46287649322.pdf
    • https://uploads.strikinglycdn.com/files/65f86d6c-cf29-4b96-bb3e-06a682a55c55/kotemutegubejosepap.pdf
    • https://s3.amazonaws.com/setaxilitozuko/profile._dat_dls_19_manchester_united.pdf
    • https://uploads.strikinglycdn.com/files/7f5843ab-90a1-4eba-82f6-a3f014cc2bc4/97329819645.pdf
    • https://s3.amazonaws.com/dixaleko/how_to_pair_my_bose_speaker_to_my_tv.pdf
    • https://s3.amazonaws.com/bovenotojitowe/muviwotiwusemedakuzito.pdf
    • https://s3.amazonaws.com/duzexefemosaxe/business_intelligence_center_site_template_missing.pdf
    • http://jezawirigi.epizy.com/apple_store_slow.pdf
    • http://kikegapel.epizy.com/vinisu.pdf
    • https://uploads.strikinglycdn.com/files/211b2cbc-1be4-46b2-ba3c-655da34fac0c/coleman_saluspa_inflatable_hot_tub_canada.pdf
    • https://s3.amazonaws.com/ponivotigegepub/21_marvel_movies_to_watch_before_endgame.pdf
    • https://s3.amazonaws.com/fajonubinomeder/conditional_exercise_with_answers.pdf
    • https://s3.amazonaws.com/rutufokedizon/nopug.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e764.bin
ad4d8f11f8dd86c8995f321e0a37c8d8eabfa35c18389165a357b3aae8b7dcdd
pdf-font-stream PDF embedded font (sfnt) at offset 0xE764 4208 bytes
font_01_sfnt_off0000f657.bin
94852a4ae3c3f9e98a390de19cfd49ab0211ddef700dc22829b296165398e2a9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF657 5112 bytes
font_02_sfnt_off000107d1.bin
ea651f37ea0a7c2adedd810bf91f107e970a01d6c15a664c424547aad0cf5f45
pdf-font-stream PDF embedded font (sfnt) at offset 0x107D1 10304 bytes