Malicious PDF — malware analysis report

Static analysis result for SHA-256 58500f261abcdb99…

MALICIOUS

PDF

88.3 KB Created: 2021-03-31 21:51:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b969187a82021074e31dfb984fc99ce9 SHA-1: c08b388d01e7916c253626af6f927da32556ab8a SHA-256: 58500f261abcdb992599ace3b723f3ed0138220c8b5d1cf1efb3be27efe1cdf8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, which is a common tactic for phishing attacks. The document body, though heavily obfuscated, suggests a lure related to a 'Ferrari scuderia watch user manual'. The presence of external URI and embedded URL heuristics, along with the ML classifier and ClamAV detection, strongly indicate malicious intent. The primary IOC is the suspicious URL found within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=ferrari+scuderia+watch+user+manual
    • http://kamini33.ru/vonojazadixafevay4mvn.pdf
    • http://reduslimitaly-ufficiale.site/vavajodanwahxz.pdf
    • http://small-italy.space/eudemons_online_apotheosis_guideyx7o7.pdf
    • http://pixxel.life/datujalanexirerelopederzuo7a.pdf
    • http://prostotit.site/examiner_report_igcse_physicsarumh.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/bb5f0ed4-c621-4362-bbad-93b860fa52cf/my_kenmore_elite_washing_machine_wont_spin.pdf
    • https://uploads.strikinglycdn.com/files/891c662d-e469-4919-8b96-fc3502387da2/atwood_furnace_repair_manual.pdf
    • https://uploads.strikinglycdn.com/files/5ebfa977-7528-4c60-97b6-c5ed1519b168/honda_hr215_transmission_fluid.pdf
    • https://uploads.strikinglycdn.com/files/e1dd2687-e704-443d-b38b-1941e007d041/acurite_rain_gauge.pdf
    • https://uploads.strikinglycdn.com/files/b540c27f-56bc-4602-b0aa-ba1cb82df51a/2008_g35_transmission_fluid_check.pdf
    • https://uploads.strikinglycdn.com/files/138ce284-8c58-4044-8ace-c0e073f20d4f/line_6_spider_v_240hc_mkii_head_review.pdf
    • http://feramivo.rf.gd/nakotapawaduzezu.pdf
    • https://uploads.strikinglycdn.com/files/7e5c3c6f-f4bb-400c-b358-0945dff0724e/57329116977.pdf
    • https://uploads.strikinglycdn.com/files/76cca757-468a-4144-a69f-2fce82bf0ce2/test_power_supply_pc_software.pdf
    • https://uploads.strikinglycdn.com/files/5ff88df7-3426-4ae1-a2a7-c7b184b5dfae/5th_edition_dd_adventure_modules.pdf
    • http://nematamaduwos.epizy.com/pre_calculus_12_textbook_mcgraw_hill_online.pdf
    • https://uploads.strikinglycdn.com/files/074829f6-2f29-441a-8087-8ecca735f9b6/noduxupilorilo.pdf
    • https://uploads.strikinglycdn.com/files/a63ceff6-1fd0-45da-a5f5-e18554b67922/17418777577.pdf
    • http://kodadus.epizy.com/vujegabezebidadobivopeju.pdf
    • http://regusew.epizy.com/jigibujik.pdf
    • http://pejefovad.epizy.com/88010094939.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011a52.bin
f0cd5123a4b5f919e237e85fdd17139250831d2c119fd2d5db07549344327495
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A52 5224 bytes
font_01_sfnt_off00012bf9.bin
24911404a6136409fc461ac1abf145b9c4c12f3b847709cae65d6a10e3a5af5f
pdf-font-stream PDF embedded font (sfnt) at offset 0x12BF9 12044 bytes