Malicious PDF — malware analysis report

Static analysis result for SHA-256 57521cecfa111834…

MALICIOUS

PDF

68.4 KB Created: 2021-03-15 02:49:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1943c7556dc2ef9bd1d49508befab112 SHA-1: b6f652dda4f8bb9ca9b137b027cf7018157fb1ba SHA-256: 57521cecfa111834c9ad367b125ed1812533ffcb5679aaa1cd9f77733ccfaada
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL leading to a website offering free movies. This is a common lure for phishing attacks or to redirect users to download malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=watch+series+movies+online+free
    • https://cdn.sqhk.co/bijukipuj/xjcgeoP/33920068308.pdf
    • https://cdn.sqhk.co/zejegure/mjchcsh/18630332414.pdf
    • https://cdn-cms.f-static.net/uploads/4493569/normal_604e8b092a430.pdf
    • https://cdn.sqhk.co/lupekute/gX6iGjd/om_nom_nom_minecraft.pdf
    • https://cdn-cms.f-static.net/uploads/4367925/normal_602dad15a376e.pdf
    • https://cdn.sqhk.co/filemowa/JibTvhi/nozugagive.pdf
    • https://cdn.sqhk.co/jawutuwek/ibhh9ib/zifiworolerimam.pdf
    • https://cdn-cms.f-static.net/uploads/4409092/normal_6039b1803a0bb.pdf
    • https://static.s123-cdn-static.com/uploads/4447915/normal_5ff0f8556ff96.pdf
    • https://cdn-cms.f-static.net/uploads/4410013/normal_602835541dd0c.pdf
    • https://cdn.sqhk.co/sivefuxonix/Cbrlge1/38221483139.pdf
    • https://cdn.sqhk.co/gapebeve/hd2AU0V/glitch_video_camera_app.pdf
    • https://cdn-cms.f-static.net/uploads/4408190/normal_602ab98f9b388.pdf
    • https://cdn-cms.f-static.net/uploads/4393890/normal_601dbfa4d7bde.pdf
    • https://cdn.sqhk.co/vetedaxuzele/hh5gjgj/24198501141.pdf
    • https://cdn.sqhk.co/fetuxudo/MgfETjf/among_us_game_wallpaper_download.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://xavemiwikujuxuk.rf.gd/40955074161.pdf
    • http://baguzakanaso.epizy.com/just_dance_2020_pour_console_wii.pdf
    • https://s3.amazonaws.com/jupoti/minitab_14_statistical_software_free.pdf
    • http://rufowafom.epizy.com/stand_by_me_ukulele_chords_c_am_f_g7.pdf
    • http://kibululugavi.epizy.com/chrome_cache_files_android.pdf
    • http://mavipob.epizy.com/70614126846.pdf
    • https://s3.amazonaws.com/welanisowari/bad_genius_full_movie_in_english.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d0cc.bin
bc9a3fe89f0dfcb306ae00fad44818659d675ab64708fe936a7b94ffe3f7bb70
pdf-font-stream PDF embedded font (sfnt) at offset 0xD0CC 5192 bytes
font_01_sfnt_off0000e25c.bin
6e2718aa097a0a68489487546250576b222e59d7d11bfe74eee40da603b80672
pdf-font-stream PDF embedded font (sfnt) at offset 0xE25C 9968 bytes