Malicious PDF — malware analysis report

Static analysis result for SHA-256 60add87455f98d84…

MALICIOUS

PDF

81.7 KB Created: 2021-04-05 01:42:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: 690199493f0c75835176bd8fa9e10fde SHA-1: 50f62ada7ad8fbeef32732131839186a47a76952 SHA-256: 60add87455f98d847cd5c1c09aa73f24f2bbd3b8c9c83c8445959d5dc9bbb1ba
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/wix?keyword=context+free+grammar+solved+examples+in+automata PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4474231/normal_5feb72d1a0ff4.pdfIn PDF document text
    • https://cdn.sqhk.co/loberutebe/jiPZhi4/2184623529.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419192/normal_5fe9c93d9a75e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4472204/normal_5ff9c577935c6.pdfIn PDF document text
    • http://mitedujonajezed.scienceontheweb.net/dark_blue_denim_jacket_mens.pdfIn PDF document text
    • https://cdn.sqhk.co/sovebiba/gichhhd/free_handwriting_name_worksheets.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393204/normal_5febf2c59d2c2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451210/normal_6061432c21d56.pdfIn PDF document text
    • http://kevebofuru.medianewsonline.com/13634950367.pdfIn PDF document text
    • https://cdn.sqhk.co/vegedusovo/bYJiiid/pro_driver_sport_car_driving_simulator_2019_mod.pdfIn PDF document text
    • http://jawunefuda.mygamesonline.org/86992920726.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://34e51215-b586-4e01-b3ea-a219475a7b91.filesusr.com/ugd/46481b_c46ab12665514c7883e6bb78ac3fc145.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/daxemo/76809029665.pdfIn PDF document text
    • https://502f924d-676a-41b3-8220-87c01882f600.filesusr.com/ugd/5a20bb_afb3c763e5ca4563ba116a5137a686ff.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/xufujofaleki/autodesk_123d_design_tutorial.pdfIn PDF document text
    • https://s3.amazonaws.com/moduxanakuri/lipowijanal.pdfIn PDF document text
    • https://s3.amazonaws.com/remuv/esc_guidelines_dyslipidemia_2017.pdfIn PDF document text
    • https://f3e0ee59-b309-4736-aefa-1db4f942b0be.filesusr.com/ugd/e87662_c7a37588cb5d43508504cf693e0c6f8e.pdf?index=trueIn PDF document text
    • http://jabafujadopus.rf.gd/the_awakened_empath.pdfIn PDF document text
    • https://85fc0914-20e3-4f1c-be8c-de7e6f89f47e.filesusr.com/ugd/a44510_546610a80a6b498e84cde6b6afc03732.pdf?index=trueIn PDF document text
    • http://fenulujexita.epizy.com/56511250796.pdfIn PDF document text
    • https://48e4e0df-78ce-4736-8797-27735e68dc67.filesusr.com/ugd/f3b179_d5ad6847524943668a249bf186bc640b.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec2f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC2F 5396 bytes
SHA-256: cf7c68eb7651985b5ea0b764dde59aa9d077597ed844b5c4743fb4412a1ac0eb
font_01_sfnt_off0000fe82.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFE82 10556 bytes
SHA-256: d92e15a4190b886b3005103e6b5b77950ae7a594124bfb6f04df42e3dcb1a029
font_02_sfnt_off000122d8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x122D8 16264 bytes
SHA-256: 1da3eac126fe54607bf39f4082daf04577f1aa250d955f58b9796ccf0a513fef