Malicious PDF — malware analysis report

Static analysis result for SHA-256 642dbec61d52e373…

MALICIOUS

PDF

80.6 KB Created: 2021-03-14 20:05:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5a4313700e945e5c6522cc7aacf59861 SHA-1: 526294700f3e07a3555f6567782d5ae31b863b9f SHA-256: 642dbec61d52e373c904f895c8dce21af8f983183044b5d4fca669f51ce7418d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URI pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also flagged this PDF with high confidence. The document body, though heavily obfuscated, contains text related to TV guides, likely serving as a lure to direct users to the malicious URL for potential phishing or malware download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=how+to+configure+ivue+tv+guide
    • http://korixoludofuguk.scienceontheweb.net/astrology_books_in_bengali_free_download.pdf
    • http://lowufadit.scienceontheweb.net/bsc_part_2_physics_practical_book_download.pdf
    • http://kexumojazo.mypressonline.com/convert_to_word_doc_freeware.pdf
    • https://cdn.sqhk.co/juvebuzizej/zjd2tgf/only_one_kanye_west_meaning_of_the_song.pdf
    • https://cdn.sqhk.co/parabeset/f01ha3k/fozarudurasav.pdf
    • https://cdn.sqhk.co/woxemumi/uZieuja/shred_downhill_mtb.pdf
    • http://pazadixokumox.sportsontheweb.net/how_to_turn_on_heat_and_glo_fireplace_without_remote.pdf
    • http://nigavereke.mygamesonline.org/how_to_fix_zoom_background_issues.pdf
    • http://rijexofugovu.medianewsonline.com/lipevovajabesunu.pdf
    • http://sunakijabe.sportsontheweb.net/behaviour_modification_definition.pdf
    • http://sujabupinoda.scienceontheweb.net/25098627368.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/1393a513-df5a-4346-8a87-47e5d3ee30f9/excelsior_college_loss_of_accreditation.pdf
    • https://uploads.strikinglycdn.com/files/34abad35-da68-4573-bba3-c27db2de1b85/68109873865.pdf
    • https://uploads.strikinglycdn.com/files/32d7e948-285b-45c1-9e37-3e35ffc48412/black_hawk_down_soundtrack_vinyl.pdf
    • http://punotonaduwize.atwebpages.com/marine_corps_medal_placement_on_dress_blues.pdf
    • http://widepidaba.atwebpages.com/70834671863.pdf
    • https://uploads.strikinglycdn.com/files/07d25357-c1b8-48e5-9d90-070eba45dfb4/sears_craftsman_router_table_25444_manual.pdf
    • http://nisetekotixob.myartsonline.com/to_kill_a_mockingbird_packet_questions.pdf
    • https://uploads.strikinglycdn.com/files/44d4a28b-7fe0-47c3-898e-1cb06cba8f74/the_secret_garden_movie_2019_trailer.pdf
    • https://uploads.strikinglycdn.com/files/8997078f-c47a-4272-a3cd-0e029ddaba99/percy_jackson_the_lightning_thief_read_aloud_chapter_6.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e844.bin
a9b7011eaf073f39c66c96f26c0f854a68228650cbdc04ff066f1042736fd9e9
pdf-font-stream PDF embedded font (sfnt) at offset 0xE844 4880 bytes
font_01_sfnt_off0000f908.bin
442cf4c3afabfef1326fcb621689a76dd9d6082eeb51d983481c7b31388a2911
pdf-font-stream PDF embedded font (sfnt) at offset 0xF908 11316 bytes
font_02_sfnt_off00011fb2.bin
a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x11FB2 16204 bytes