Malicious PDF — malware analysis report

Static analysis result for SHA-256 6443ca573bc2488c…

MALICIOUS

PDF

89.9 KB Created: 2021-04-24 22:23:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e7a9de614f505ef73d53ade0bfe9440d SHA-1: 9adc4c3e47af888b9514805c0984783bc821067f SHA-256: 6443ca573bc2488c9cc5147533fe40b83f80e9d2c428a7435ef2044e26552b8b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that, when clicked, leads to a URL containing a search query for song lyrics, suggesting a social engineering lure. While no scripts were explicitly extracted, the PDF structure and embedded URI indicate an attempt to redirect the user to a malicious domain, likely for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=i+can%2527t+help+falling+in+love+with+you+lyrics+elvis+youtube
    • http://movawizaxaxato.mywebcommunity.org/92211460009.pdf
    • http://pivojowemetobiv.mywebcommunity.org/medicamentos_antiflatulentos.pdf
    • http://xiwesesakuvel.medianewsonline.com/best_convection_microwave_oven_in_india_2020_under_10000.pdf
    • http://xejopegig.mypressonline.com/enemy_pie_art_activities.pdf
    • http://morasufas.iblogger.org/2128489987.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/3a08c9ec-4fe6-422a-8fe8-609d28b878b7/fubobuwafasobawonu.pdf
    • https://s3.amazonaws.com/janodojivi/dazanukagusino.pdf
    • https://s3.amazonaws.com/dudurat/alexander_hamilton_book_biography.pdf
    • https://s3.amazonaws.com/gajabedafot/introduction_to_computing_systems_from_bits_and_gates_to_c_and_beyond_answers.pdf
    • https://s3.amazonaws.com/nokiva/global_competitiveness_report_2014-_15.pdf
    • https://uploads.strikinglycdn.com/files/9822a833-dd0f-46a5-bc96-0e74df457590/tnteu_lesson_plan_format_for_computer_science.pdf
    • https://uploads.strikinglycdn.com/files/be1791e7-5cd3-4bd8-b241-7edd26228470/limejimapiro.pdf
    • https://uploads.strikinglycdn.com/files/c4f133f9-57aa-436e-aced-a148d4c96f83/68233124225.pdf
    • https://s3.amazonaws.com/pasawe/zidesaxez.pdf
    • http://zubeleboju.epizy.com/aap_bright_futures_guidelines_for_health_supervision.pdf
    • http://tibutariwu.myartsonline.com/counseling_case_study_examples.pdf
    • http://xogijowag.onlinewebshop.net/90792254532.pdf
    • http://wejajesenopezoj.onlinewebshop.net/logical_operators_in_c_programming_with_example.pdf
    • https://s3.amazonaws.com/bodajaku/21055797814.pdf
    • https://s3.amazonaws.com/tesodagiwor/tijevek.pdf
    • https://s3.amazonaws.com/jokotaziweluge/13569188719.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011d50.bin
a29b1bd827ca057d456e6d1ffb157416340bd0dc40e429abb848d0dbb9c17ac4
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D50 5644 bytes
font_01_sfnt_off000130a1.bin
874eaf0d2c2e3cecd42ef568c337451b5aba40799cf43bb27fdf0fc53aab21f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x130A1 12504 bytes