Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e101482fde359d4…

MALICIOUS

PDF

78.0 KB Created: 2021-04-02 06:55:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 77ea60d7450b7bbdde7a66f3f21391f5 SHA-1: 72a68c9d17e74131d215195491d162920367e33d SHA-256: 5e101482fde359d42d26584e00520139fb9bf88cbf2e293a40bcaa48b67a458f
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. It uses a fake browser/software-install lure. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=how+to+block+websites+on+android+firefox PDF link annotation
    • http://sdorovie-sustavi.xyz/what_is_the_main_theme_of_gone_with_the_wind7u96n.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4414172/normal_5ff0429674105.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403679/normal_5ff43203f0ea2.pdfIn PDF document text
    • http://granitmetrospecstroy.ru/tadejupuworigidevajibevuxlfq0.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4495269/normal_5ff4396e5d5c0.pdfIn PDF document text
    • http://idslim-italia.site/2707995815790h3g.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4387581/normal_5fe2d4552b0a9.pdfIn PDF document text
    • http://rezonansmusic.com/race_to_witch_mountain_in_hindi_hd_downloadrftc5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4458623/normal_60447414f28db.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4460045/normal_601bfdf590d86.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366653/normal_6056ec46abf7c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4423699/normal_60557e676eb29.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4417670/normal_5fe50160b17c4.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/a671923d-ebe3-46cf-8e39-b916d53d17f3/whirlpool_cabrio_gas_dryer_thermal_fuse.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3a6d29f0-8c71-4bd0-9916-2b819de5ddda/how_to_update_firmware_on_lg_smart_tv_uk.pdfIn PDF document text
    • https://s3.amazonaws.com/luropi/gold_brick_guide_lego_marvel_superheroes.pdfIn PDF document text
    • https://s3.amazonaws.com/fewunadupop/how_to_be_the_best_financial_advisor.pdfIn PDF document text
    • https://s3.amazonaws.com/xetasif/are_social_workers_in_high_demand_in_south_africa.pdfIn PDF document text
    • https://s3.amazonaws.com/wujanozo/sample_safety_plan_for_sex_offenders.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3ff2fbeb-d8b0-40a1-a2a6-a6d3d316fd72/48531052431.pdfIn PDF document text
    • https://s3.amazonaws.com/gurowozenupifi/59788587965.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2c3b9881-054f-40c9-92d7-e283daf2a223/nespresso_vertuoline_troubleshooting_blinking.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/04d78a93-a993-42fc-ae6f-57d69973361a/57216308898.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF1EC 5340 bytes
SHA-256: e8b5d37c3b60467a4e8fcfa563ec91c008bb7b987d01d032ba13c6ec6221f30e
font_01_sfnt_off00010437.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10437 11172 bytes
SHA-256: 89dbc38c50b7c9fdd74976f2ff8a49b4874104f3428611c937094784560a3d9e