Malicious PDF — malware analysis report

Static analysis result for SHA-256 5dce844f1ff128de…

MALICIOUS

PDF

107.5 KB Created: 2021-03-20 06:50:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5167c88e21efa98cd5f4072077de9168 SHA-1: 250ebd8705c5fed47ee3ea8028c34adda3e4504d SHA-256: 5dce844f1ff128de5aa8f98c3493469927213e7cde2333af2a9d3a17a8c28d48
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, mezovuduw.ru, which is likely used for phishing or to serve malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, potentially as part of a phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=sheridan+le+fanu+carmilla+pdf
    • https://cdn.sqhk.co/zunesunatiri/iggHkih/milinejenenuvux.pdf
    • https://static.s123-cdn-static.com/uploads/4495058/normal_6004759fae75f.pdf
    • https://cdn-cms.f-static.net/uploads/4445573/normal_603f68c654d17.pdf
    • http://zdorovie-vashe-vse.xyz/star_trek_discovery_season_3_episode_6_review_ign9oyew.pdf
    • https://cdn.sqhk.co/sovebiba/N3hikha/new_latest_bollywood_ringtone_2020_download.pdf
    • https://cdn-cms.f-static.net/uploads/4384639/normal_60192538108e1.pdf
    • https://kopojari.weebly.com/uploads/1/3/4/5/134585935/6182004.pdf
    • http://sq11mini.com/jajisefk9qlf.pdf
    • https://vataripisak.weebly.com/uploads/1/3/4/6/134600115/lazefugimusigudux.pdf
    • https://kuzogirig.weebly.com/uploads/1/3/4/7/134748708/gadujusunonazi.pdf
    • http://50offstore.info/basic_guitar_chords_chart_for_beginnersltokh.pdf
    • https://cdn.sqhk.co/wevexifimur/iilB8ha/stick_cricket_super_league_division_1_final.pdf
    • https://static.s123-cdn-static.com/uploads/4385880/normal_5ff9db1c549e7.pdf
    • http://airet.space/leatherman_rebar_blackr49gc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vaxebisapesi/idsa_guidelines_neutropenic_fever_2018.pdf
    • https://s3.amazonaws.com/wiwuxot/siset.pdf
    • https://0ffdd24b-620b-4f4d-94ef-a39da1ca20bd.filesusr.com/ugd/853ce2_102b20abd11e436f9083665ff9a52d1c.pdf?index=true
    • https://s3.amazonaws.com/nelizenejakarug/word_document_corrupted_recovery.pdf
    • https://s3.amazonaws.com/gedesisumi/jelufirofozedew.pdf
    • https://s3.amazonaws.com/difigomisosak/arteriovenous_malformation_of_cerebral_vessels_treatment.pdf
    • https://2a4c341d-9af7-4f89-b48a-1b926ad6ced7.filesusr.com/ugd/dd6616_4c7c264534104902b3a08bbdb3e1cfac.pdf?index=true
    • https://9f9bd9fa-00fe-4673-b34e-9a629881f524.filesusr.com/ugd/09273f_fc69e11d9ec549d6bb531e51caa227b3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00016709.bin
19eb4d914445d0d732c3fa947182a8e4d4e0632614db2c863543076331964434
pdf-font-stream PDF embedded font (sfnt) at offset 0x16709 5320 bytes
font_01_sfnt_off000178f5.bin
f12b7bc9f813e53144547cd96ca008f376228b9585ddfc1e5283b36afa4f5141
pdf-font-stream PDF embedded font (sfnt) at offset 0x178F5 12392 bytes