Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d1edc6ce0e97a08…

MALICIOUS

PDF

128.7 KB Created: 2021-04-02 13:53:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ba0c9c91ecc45937e0fbfcbc71170654 SHA-1: 237d23cf122dfcccaf46c4d79489e14fba3d8e64 SHA-256: 5d1edc6ce0e97a080c198bff1d9b75a2a0c70361bd37b4b4c0a6ee2b87839154
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by ML classifiers and ClamAV as malicious. It contains multiple embedded URLs pointing to potentially malicious content, suggesting it's used for phishing or malware distribution. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' indicates the document may instruct users to open a password-protected archive, a common tactic to bypass security filters.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=hobbes+de+cive+pdf+espa%25C3%25B1ol
    • http://fineagencyy.com/venta_de_bomba_de_ariete_en_ecuadorlq2fs.pdf
    • http://pitushok.space/samsung_dvd_player_bd-jm57c_remotedw9ge.pdf
    • http://wodedutipif.medianewsonline.com/wolkenstein_problems_general_physics_solutions.pdf
    • https://cdn.sqhk.co/kavejufa/hbYvnQR/filelakenoxajibemon.pdf
    • http://kojijeku.mygamesonline.org/burger_king_open_near_me.pdf
    • https://cdn.sqhk.co/moxinivo/e9qWQKE/dragon_warrior_monsters_gameshark_experience_code.pdf
    • http://beliyden.xyz/performance_management_system_in_accenture25kax.pdf
    • http://zizodoroluxonaf.sportsontheweb.net/assr_1611.pdf
    • https://cdn.sqhk.co/xunijejozi/hfWiigh/17423650821.pdf
    • http://nabavawuzafurur.mygamesonline.org/30029779388.pdf
    • https://cdn.sqhk.co/niririga/jc3giji/vogudefaxiju.pdf
    • http://cheapkeys.site/lepisufigokituwuziduwydkyb.pdf
    • https://cdn.sqhk.co/sejiragidu/jagjjjv/42765423439.pdf
    • https://cdn.sqhk.co/xinulezebi/Zhhr039/40919403093.pdf
    • http://wokodanib.getenjoyment.net/list_of_abstract_nouns_from_verbs.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/dutuzanob/energie_non_renouvelable_definition.pdf
    • https://s3.amazonaws.com/jukezeluf/boy_scout_uniform_store_in_quezon_city.pdf
    • https://s3.amazonaws.com/gezejoputiwinu/68180439377.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001ad19.bin
4a4e2b8f151a3d34d34043fffcfcd61d2a8788409caf3b0db8e855ca73d2e823
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AD19 5028 bytes
font_01_sfnt_off0001be30.bin
148c81d844482c7d60a6f70f367268140f97502512edaf243497d47c39a1fecc
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BE30 12144 bytes
font_02_sfnt_off0001e4f8.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E4F8 4324 bytes