Malicious PDF — malware analysis report

Static analysis result for SHA-256 5dff906536d0e548…

MALICIOUS

PDF

86.4 KB Created: 2021-03-22 15:04:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-10
MD5: 7657223ce0cb3d1ce2ea8d98d8e27a1b SHA-1: aa193a2a919a31d20ed76fb2526bcb55899da923 SHA-256: 5dff906536d0e54846dc052691dcc4e75080eba3ce6a2ded2b38d16f20cea1d0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to 'jumiwimov.ru', which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, appears to be related to the URL's keyword, suggesting a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=gsus+chord+meaning PDF link annotation
    • https://cdn.sqhk.co/mamidusidozu/yhcJHjH/learn_to_code_free_offline_app_download.pdfIn PDF document text
    • https://cdn.sqhk.co/vozeseseber/1Pjehbj/riders_republic_ubisoft_price.pdfIn PDF document text
    • https://cdn.sqhk.co/nikapeke/yicvijh/urban_drug_empire_apk_mod.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/f237c967-e4e3-4b4c-a480-9c4aeb0f1124/liruluxanizel.pdfIn PDF document text
    • https://s3.amazonaws.com/wemupajese/29701807719.pdfIn PDF document text
    • https://s3.amazonaws.com/jiwisigetizoxif/dekofugesenozesoxu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3b373c80-4e07-4540-a89a-3a7755c14267/27986077605.pdfIn PDF document text
    • https://s3.amazonaws.com/wefadep/the_strangest_secret_by_earl_nightingale_download.pdfIn PDF document text
    • https://s3.amazonaws.com/zafirawit/bunapimitiwup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e755bae3-1282-49ce-8411-7b0dbedc5c85/jetafojovubos.pdfIn PDF document text
    • https://s3.amazonaws.com/poresi/beauty_and_the_beast_book_cover_printable.pdfIn PDF document text
    • https://s3.amazonaws.com/kesumasaka/will_there_be_another_part_to_twilight_movie_2019.pdfIn PDF document text
    • https://s3.amazonaws.com/kozibowisenatu/15346845695.pdfIn PDF document text
    • https://s3.amazonaws.com/sizabo/timely_alarm_clock_pro_apk.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e2b0ee3a-21de-4a93-81b2-47d0b0214494/54577578731.pdfIn PDF document text
    • https://s3.amazonaws.com/tarizirefevifab/38805590663.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fa823289-e3d7-4e4c-804b-8c9474d1898c/why_is_the_bevel_of_the_needle_always_slanted.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/65ef941c-d3ec-47f1-9e81-d0db23f09ed3/70852108414.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/049f50fc-c207-492b-84eb-e9dd6651cd11/5122204374.pdfIn PDF document text
    • https://s3.amazonaws.com/xalexojaxipud/casio_baby_g_shock_5001_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/zasepo/31686605141.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f27f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF27F 5352 bytes
SHA-256: 757ab96fafba8aac1e4d828c7e53db000ea725bd759f3d7827fb42912bf1dc0d
font_01_sfnt_off00010483.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10483 1800 bytes
SHA-256: e9a5a1f6ed95b1e3669933bb00002ad32a1708c3e0b735191cad5e02368a6c7d
font_02_sfnt_off00010d11.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10D11 11744 bytes
SHA-256: 31fd6b2cdeae14905033de0e112e164845c565448427a0a7cff646b75f2ebdad
font_03_sfnt_off0001356c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1356C 16120 bytes
SHA-256: 184efd0e138a9418359f6897f9ac56b5cd93cafbd57abf30711ac2aee7e18832