Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b295a0a55538bf6…

MALICIOUS

PDF

206.9 KB Created: 2020-04-05 04:21:37 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: 5c541c06b8d325b4497c7f736095767b SHA-1: 1cc82227c9e257195f5e7d41e6c875c1fa2ebc89 SHA-256: 5b295a0a55538bf6838eb110052c693495ed26a00ca8ec91aa78703d28fdb967
76 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains multiple embedded URLs and a heuristic firing for a clipboard command execution lure, indicating an attempt to trick the user into running commands. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves social engineering to execute arbitrary commands, likely to download and run a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8317

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://djtrukka.com/uploads/1/3/0/2/130289653/130289653.html#que+es+la+matriz+extracelular+y+como+esta+compuesta
    • http://diamonddanesranchllc.com/uploads/1/3/0/4/130436033/werekozaniwati-sojuwirebukof.pdf
    • http://enwranch.com/uploads/1/3/0/3/130379548/6834676.pdf
    • http://ivyrhodes.com/uploads/1/3/0/7/130776518/nikija.pdf
    • http://optronics.us/uploads/1/3/0/6/130604808/899137.pdf
    • http://pleiadesartsllc.com/uploads/1/3/0/5/130550930/1620066.pdf
    • http://blackstarwines.com/uploads/1/3/0/2/130289741/9434797.pdf
    • http://jotthemdown.com/uploads/1/3/0/6/130621818/e0aa332.pdf
    • http://lisahatchmillinery.com/uploads/1/3/0/6/130620429/47f0ca.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002e803.bin
970422c4928a6404be3a119f915a2a834fb8a5c24115fb29fc42fccb1d5985ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x2E803 9968 bytes
font_01_sfnt_off00030a42.bin
b878b95aa29e559efc224dc6bc3b57920b6be1adc6de8eb46e17207a04fede45
pdf-font-stream PDF embedded font (sfnt) at offset 0x30A42 3680 bytes
font_02_sfnt_off000316f0.bin
9d429dbece8d08ec595a91ed96f9a29f7101465a11ba2e97aa8138b1adb5ba85
pdf-font-stream PDF embedded font (sfnt) at offset 0x316F0 16172 bytes