Malicious PDF — malware analysis report

Static analysis result for SHA-256 5fcc68b6e794196e…

MALICIOUS

PDF

69.2 KB Created: 2021-03-04 09:40:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7132a32b28beacbdbd78f4b6686ab905 SHA-1: b9d5ddc63b1dd402f6380c61f31dae5f8e54a31d SHA-256: 5fcc68b6e794196efd9d0c180c6c7fea681509a72ca62c7dbef4e5da12523112
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also flagged this PDF as malicious. The document body, though heavily obfuscated, contains text related to 'Mickey mouse clubhouse ukulele chords', likely a lure to direct the user to the malicious URL for a phishing or malware download attempt. No scripts were extracted, but the presence of external URIs and the high confidence malicious verdict indicate a phishing or trojan delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=mickey+mouse+clubhouse+ukulele+chords
    • http://komaxinatobofe.medianewsonline.com/dark_knight_script_joker_interrogation.pdf
    • http://mujabelor.mywebcommunity.org/75512202849.pdf
    • https://cdn-cms.f-static.net/uploads/4387056/normal_6032d7f3953cc.pdf
    • http://nemeloru.66ghz.com/the_lover_marguerite_duras_espaol.pdf
    • http://borejukeluteva.mygamesonline.org/70676687074.pdf
    • http://faxusigeroles.sportsontheweb.net/zafolinive.pdf
    • http://kenugizi.getenjoyment.net/33488135794.pdf
    • https://cdn-cms.f-static.net/uploads/4417037/normal_5fe709fc737e4.pdf
    • http://wiwovurezibaso.getenjoyment.net/what_are_the_components_of_the_structure_of_an_argumentative_essay.pdf
    • http://nakodinita.scienceontheweb.net/g_shock_ga_100_red_black.pdf
    • https://cdn-cms.f-static.net/uploads/4373016/normal_601fef3505f47.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zikoliduxa.atwebpages.com/xamabopopesowebe.pdf
    • http://kepagewav.atwebpages.com/how_to_make_someone_fall_in_love_with_you_wikihow.pdf
    • http://dijuvunote.onlinewebshop.net/82550779452.pdf
    • http://rodedewezijore.atwebpages.com/lean_manufacturing_training_uk.pdf
    • http://rixibedi.onlinewebshop.net/8480881406.pdf
    • http://xovolefewawex.atwebpages.com/32214076703.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d2ae.bin
51ac7b6d1c3637bec64c72969dbd5e3044ebeba1dfa93011a381b5c809c7ba8e
pdf-font-stream PDF embedded font (sfnt) at offset 0xD2AE 5280 bytes
font_01_sfnt_off0000e48c.bin
7426a3acd4e0f4e3d5d54902ff7e5bcc11eabfe59c7b04faf5288d449ce6797f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE48C 10276 bytes