Malicious PDF — malware analysis report

Static analysis result for SHA-256 5d3cf10cbc708272…

MALICIOUS

PDF

84.3 KB Created: 2021-03-08 16:14:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b54d9c40932d82ab869fdb12e43bfac3 SHA-1: d1f66b2622508e9836647ae1fecd17ffab73cc8d SHA-256: 5d3cf10cbc7082729ae5bfa77ffbcfb8bd286258e8e6d0306a6f471a736d0354
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, disguised as a link for free Christmas piano sheet music. This indicates a phishing or social engineering attempt to redirect the user to a malicious site. The ML classifier and ClamAV detection strongly support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=free+easy+printable+christmas+piano+sheet+music
    • https://vinifobak.weebly.com/uploads/1/3/5/2/135298549/b7d2ddaf94e49c.pdf
    • https://tavifarexup.weebly.com/uploads/1/3/4/6/134611028/xazomubinesig.pdf
    • https://cdn.sqhk.co/letonolomo/ic6Mggm/lariruduvuduxe.pdf
    • https://cdn.sqhk.co/vemegunir/ihihokE/ice_cream_jump_rope.pdf
    • https://cdn.sqhk.co/kulamogo/biqyhdU/princess_castle_hotel_disneyland_paris.pdf
    • https://xafinuwexedigu.weebly.com/uploads/1/3/1/3/131379324/tepagisusanujil_rofifuzafusiza_kuretenutiruz_zaxul.pdf
    • https://tebideronapiza.weebly.com/uploads/1/3/1/4/131483209/4657624.pdf
    • https://fomiradoxep.weebly.com/uploads/1/3/4/5/134512134/7218698.pdf
    • https://cdn.sqhk.co/nilamemiw/ciahdhd/maze_runner_labyrinth_wiki.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/53a4fdc0-c71b-4824-bea8-d775d411b3dc/vakovixulasulemelodim.pdf
    • http://daloketo.epizy.com/android_x86_intel_graphics_driver.pdf
    • http://vedisupekak.epizy.com/32302935461.pdf
    • https://s3.amazonaws.com/fekaduvopigab/81914145187.pdf
    • https://s3.amazonaws.com/xubifupi/maus_1_francais.pdf
    • https://s3.amazonaws.com/gedexim/chamberlain_liftmaster_professional_gate_opener_manual.pdf
    • https://uploads.strikinglycdn.com/files/dcd668df-8a55-4d32-8485-eb0b7ec653ec/how_to_pronounce_american_accent.pdf
    • https://uploads.strikinglycdn.com/files/6486b6e2-5d29-49a2-9754-4ce7f77cee49/68555162127.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f6c1.bin
d4b84b3bf2266b458a714c48c15dcf69cee32ae2f8b222c5481d938fa9db96dc
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6C1 5372 bytes
font_01_sfnt_off000108dd.bin
3c674ee1d609a175d504d076733bdc285b56f3e7f051206061bda84ae9fa4159
pdf-font-stream PDF embedded font (sfnt) at offset 0x108DD 11108 bytes
font_02_sfnt_off00012e84.bin
d973db94ba2c448c661c26f08d051ac794e7cb4f3c7daa33c2141e8036f071b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E84 16100 bytes