Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c4a9066f3e18f15…

MALICIOUS

PDF

161.7 KB Created: 2021-03-31 17:09:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1e67b2052cbe722b0f1b25a08f35bd1d SHA-1: dae05f45e93607f848d57c13f3cc268a01118522 SHA-256: 5c4a9066f3e18f15ed183d3e8c3d368ec32eb564dcf58b9d5f4d78f469fda003
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating the presence of an external URI. The document body, though truncated, suggests a lure related to a printer manual. The embedded URL points to a domain that is likely part of a phishing operation to deliver further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=bizhub+c554e+manual
    • http://naturelofo.mypressonline.com/ashrae_hvac_fundamentals_handbook.pdf
    • http://gadatoreneperil.mygamesonline.org/44407152749.pdf
    • https://cdn.sqhk.co/wixefawoz/6iisHhb/marinijadegugejuniva.pdf
    • https://cdn-cms.f-static.net/uploads/4416664/normal_5fd17d2abfc8a.pdf
    • https://cdn.sqhk.co/baponakazu/ieiiJig/94104618337.pdf
    • http://tusiteguluvora.getenjoyment.net/alcoholism_information.pdf
    • http://classicalnaturally.com/geridararn6okc.pdf
    • https://cdn.sqhk.co/jotenitix/QjhTifb/6781583828.pdf
    • https://cdn-cms.f-static.net/uploads/4382614/normal_6054209236467.pdf
    • https://cdn.sqhk.co/ponajadu/Lgd77ih/zubuzadikepilesirokev.pdf
    • http://serviceforyou.site/31390819361ad76v.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://bodegifu.atwebpages.com/nokoxezinoru.pdf
    • https://s3.amazonaws.com/gawabog/68930897208.pdf
    • https://s3.amazonaws.com/zunaporam/sunixujufu.pdf
    • http://misanedajog.myartsonline.com/leboxijaniku.pdf
    • https://s3.amazonaws.com/xixonu/canon_in_d_violin_sheet.pdf
    • https://uploads.strikinglycdn.com/files/126a14c1-d936-4497-be4f-1d0d06bd9d27/linksys_ea4500_manual_espaol.pdf
    • https://uploads.strikinglycdn.com/files/fc6608b7-31e2-424b-aca3-2990a2ec9392/budonagesewuvorevaguwid.pdf
    • https://uploads.strikinglycdn.com/files/a9e51dfc-bd26-420d-88c2-202427352cd3/rejuweri.pdf
    • https://uploads.strikinglycdn.com/files/849da613-e309-430e-8203-476a6e77ed71/martin_luther_king_famous_speech_youtube.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00022d57.bin
ce22c8eaa1f53a77d563481fc3f0abc202627ce0e69ac912df19b60822d178aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x22D57 3724 bytes
font_01_sfnt_off00023a94.bin
00fc5dfa8d4762568279797457c210a00394cae61860fc80df5f0ac6a93c93cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x23A94 5216 bytes
font_02_sfnt_off00024c47.bin
da175cbd4d4206749f64361d3d32da3e25a2dfa6f6a88c6b009a78e93b402c90
pdf-font-stream PDF embedded font (sfnt) at offset 0x24C47 13376 bytes