Malicious PDF — malware analysis report

Static analysis result for SHA-256 5612959931452702…

MALICIOUS

PDF

64.1 KB Created: 2021-03-26 12:14:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ba4aa1e5b0077cdbcf0f3b275b072d78 SHA-1: d5e80c08c54744ef22ec607714ad26f5f94bba56 SHA-256: 56129599314527028e9e73c6b1f25ef5843b1c9f1ca6ad83425ccc660288b7f1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains multiple embedded URLs, one of which, 'https://lozipotod.ru/123?utm_term=cisco+ise+1.+4+licensing+guide', is presented in the document body and appears to be the primary lure. The document's structure and embedded content suggest it's designed to trick users into clicking on malicious links, likely leading to further malware download or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=cisco+ise+1.+4+licensing+guide
    • http://likelid.xyz/biedermann_und_die_brandstifter_interpretationtcnzt.pdf
    • http://wedevaz.sportsontheweb.net/nifonorobenaxisaguvapase.pdf
    • http://wonizojaru.scienceontheweb.net/thom_hogan_d500.pdf
    • https://static.s123-cdn-static.com/uploads/4392651/normal_6006b713aedcc.pdf
    • http://mnatural.space/fipudugonapk19c.pdf
    • https://static.s123-cdn-static.com/uploads/4405195/normal_5fc6216f5dd20.pdf
    • https://cdn-cms.f-static.net/uploads/4496580/normal_6043bd5b11c29.pdf
    • http://daravto18.ru/dayton_band_saw_parts_manualsk6ld.pdf
    • http://reduslimitalia.site/kymco_agility_50_scooter_repair_manual10zvs.pdf
    • https://cdn-cms.f-static.net/uploads/4450727/normal_600f4f313a585.pdf
    • http://lumobumekola.getenjoyment.net/should_internet_be_capitalized.pdf
    • http://voirly.xyz/nisaloteri5l6tk.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/4b2cbda4-45a2-41d9-8929-ae11262505a3/xufubijozonamokovod.pdf
    • https://uploads.strikinglycdn.com/files/a4475a36-d880-466e-9d97-509ceb9bd62d/what_skills_are_required_for_managers.pdf
    • https://uploads.strikinglycdn.com/files/b433f1e2-4b69-4de6-9571-d52ada0dfbdc/dewen.pdf
    • https://s3.amazonaws.com/xapota/jocko_willink_discipline_equals_freedom_audible.pdf
    • https://s3.amazonaws.com/rebesudanolo/nike_air_force_1_all_white_black_swoosh.pdf
    • https://uploads.strikinglycdn.com/files/2316b148-2dcf-49f3-9c88-830d7eae6f99/united_limo_schedule_ohare.pdf
    • https://uploads.strikinglycdn.com/files/3dfb21fc-60d5-4518-a9a0-07ab7138b152/peavey_vypyr_vip_2_bass_review.pdf
    • https://uploads.strikinglycdn.com/files/77240551-534c-4431-b671-821a4ac7da68/29731323720.pdf
    • https://uploads.strikinglycdn.com/files/d2b8f0ec-4f49-4dc9-8126-5a2f3b75fd03/wuvoj.pdf
    • https://s3.amazonaws.com/zodererezuzuxi/who_is_america_season_1_episode_1.pdf
    • https://uploads.strikinglycdn.com/files/bdbf4dc4-5360-495c-ba82-7b0eaea85823/34846388892.pdf
    • https://s3.amazonaws.com/zugutixe/photo_editor_background_hd_pictures.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c476.bin
41952f4e755352dc8bb971199a8e2f91269aebdab39e10a3479c14bff38bb550
pdf-font-stream PDF embedded font (sfnt) at offset 0xC476 4876 bytes
font_01_sfnt_off0000d531.bin
d7e853d7c40a3586c0e54b8e4d6a5ce14e851d4fa63312bfac6f8b23f904bbe5
pdf-font-stream PDF embedded font (sfnt) at offset 0xD531 8700 bytes