Malicious PDF — malware analysis report

Static analysis result for SHA-256 5449fd1677fba40e…

MALICIOUS

PDF

1.16 MB Created: 2021-03-16 13:02:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: 0c95fda939bfbbf3b7cfafa26dde71e1 SHA-1: 08fb0942a3892b54193d2f09a70dfd3d8f5bf3a1 SHA-256: 5449fd1677fba40effa2954165ffdc6dbec7ca73ef8727e8842ccb6f86e27315
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded JavaScript and multiple external URLs, indicating an attempt to redirect the user to malicious content. The ClamAV detection and heuristic firings strongly suggest a phishing or trojan distribution attempt. The embedded JavaScript likely facilitates the download or execution of a second-stage payload.

Machine Learning

  • Nyx PDF Classifier clean score 0.0182

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=an+introduction+to+applied+linguistics+norbert+schmitt+pdf+free+download PDF link annotation
    • https://moxuvobojivoz.weebly.com/uploads/1/3/0/8/130873852/bojisekemozugufuw.pdfIn PDF document text
    • https://falojixij.weebly.com/uploads/1/3/4/8/134878909/baduxajelufek.pdfIn PDF document text
    • http://zanovekolasin.mywebcommunity.org/define_addition_of_vectors_in_physics.pdfIn PDF document text
    • http://mixezitubut.mygamesonline.org/dell_latitude_e6530_bluetooth_driver_download.pdfIn PDF document text
    • https://cdn.sqhk.co/sexifirume/VEYhfjj/3d_model_free_fbx.pdfIn PDF document text
    • http://beststudent.fun/aws_default_vpc_cloudformation_templateo8l2c.pdfIn PDF document text
    • http://tells.fun/reference_angles_in_radians_worksheet8hhpn.pdfIn PDF document text
    • http://kakafeg.scienceontheweb.net/homer_the_odyssey_robert_fagles_audiobook_free.pdfIn PDF document text
    • http://shoop-fe.ru/states_with_the_lowest_covid_numberskrxuk.pdfIn PDF document text
    • http://nebo-baikala.ru/what_does_credit_decision_meanu9opf.pdfIn PDF document text
    • https://cdn.sqhk.co/lunabati/gfheib6/49374339504.pdfIn PDF document text
    • http://pristav.pro/axial_scx10_iii_jeep_jlu_wrangler_rtr4c2f5.pdfIn PDF document text
    • https://cdn.sqhk.co/dijawagag/i5gcTL7/top_songs_2020_hip_hop.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://6cdb29d4-22ce-4aaf-9e51-562b59d50851.filesusr.com/ugd/1b20fb_2cd1fc900dcb4aff986ba090e8ec56f0.pdf?index=trueIn PDF document text
    • https://5c817321-7c0c-448b-959d-deb1da9fd788.filesusr.com/ugd/19103d_c655948470f74a98bd961a2ff6638399.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/rewepalazamiso/56132031067.pdfIn PDF document text
    • https://s3.amazonaws.com/taturi/6097479820.pdfIn PDF document text
    • https://0aa989e7-076c-475f-bc22-fff5ae310860.filesusr.com/ugd/b44be6_2baa44c5c9764b4ebaad6c930ee17c40.pdf?index=trueIn PDF document text
    • http://rabatelekovufar.myartsonline.com/sakajudogipiruz.pdfIn PDF document text
    • http://nufiwimuzobo.onlinewebshop.net/how_do_i_connect_my_swann_camera_to_my_tv.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00120310.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x120310 5788 bytes
SHA-256: 6be40577e388daf12636237f677d09a028bb2e3971bb203f9470f9049f9530ff
font_01_sfnt_off001216b0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1216B0 17760 bytes
SHA-256: 50a6dc32830db3ea6a880db6a860be0aa6e78583db3bd8f61afc1a2dfc5be037
font_02_sfnt_off00124dd3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x124DD3 16628 bytes
SHA-256: 86fc11f162ee990647dff6b7da08dc2052ee54e2c7214901ce992d42f52417be