Malicious PDF — malware analysis report

Static analysis result for SHA-256 53ba1c45dea7a0b3…

MALICIOUS

PDF

84.0 KB Created: 2021-05-18 13:45:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9fb64df1d11ac633e1e94f5d05a3f70b SHA-1: e25bc0a690e0f17993b47bcfc265b822a0ce4f63 SHA-256: 53ba1c45dea7a0b371953188b7645fc58c83c7a1be9efd7763a77e3c38ce8b6f
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a lure for downloading a game, indicated by the document body and the embedded URL. The ML classifier and ClamAV detection strongly suggest malicious intent, likely phishing or malware distribution. The presence of an external URI points to the download source.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=download+gta+5+demo+setup+highly+compressed
    • https://static.s123-cdn-static.com/uploads/4380691/normal_5fcf963fcf385.pdf
    • http://butunorewezot.22web.org/cambridge_english_empower_b1_free.pdf
    • http://wubarikenokepi.iblogger.org/45741512461.pdf
    • https://cdn-cms.f-static.net/uploads/4443372/normal_6046758c0f908.pdf
    • https://static.s123-cdn-static.com/uploads/4418993/normal_60069bd63f12d.pdf
    • https://static.s123-cdn-static.com/uploads/4477138/normal_5fecf6fb718a7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/459928e6-b3d1-4486-9832-47f29c9781dd/multiplication_chart_1-30_printable.pdf
    • https://s3.amazonaws.com/banula/72595733958.pdf
    • https://s3.amazonaws.com/luramamelolem/75040869154.pdf
    • http://jigipowomazavas.rf.gd/how_to_find_the_centre_of_enlargement_and_scale_factor.pdf
    • http://kagomovibinat.rf.gd/49663127315.pdf
    • https://s3.amazonaws.com/sigobija/picsart_app_free_for_windows_10.pdf
    • http://wavopomop.rf.gd/42142933721.pdf
    • https://uploads.strikinglycdn.com/files/16e5b5e2-7db7-43fd-9e1f-553d1fe7950f/how_much_does_it_cost_to_run_a_portable_ac.pdf
    • https://s3.amazonaws.com/vavapekadoliti/case_conceptualization_template_cbt.pdf
    • https://s3.amazonaws.com/tezude/roselidetopazo.pdf
    • https://uploads.strikinglycdn.com/files/e4478bda-bc83-42a7-830b-d51ac4d517d3/what_are_the_most_controversial_topics_in_computer_science.pdf
    • http://wodebupikeziv.epizy.com/balinetekotejikejakuladal.pdf
    • https://s3.amazonaws.com/wisuw/92293612936.pdf
    • https://uploads.strikinglycdn.com/files/3c60b21a-18c9-42d6-9878-5ab0c47fb805/ge_advantium_120_light_bulb_replacement.pdf
    • http://mubomapobe.epizy.com/axes_io_mod_apk_terbaru.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001069c.bin
975b3ee56788dde4ed2e41f69e891d39e88da74272a147ad0bc285919751a8a7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1069C 5804 bytes
font_01_sfnt_off00011a5b.bin
f26e046ff8e37638a8c6e65c0ddeb8edce0aa630321de03d8623a419079c3d40
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A5B 11800 bytes