Malicious PDF — malware analysis report

Static analysis result for SHA-256 650f0582f984c42c…

MALICIOUS

PDF

79.5 KB Created: 2021-03-28 18:18:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4e0606a5d037c5e2bdc8cc553c0c762e SHA-1: db50275030ef9ed1e19414fe74fd268236d38d66 SHA-256: 650f0582f984c42cb86f995801a36a999631fb6c2c870d4dd0ac44f1468dfae5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, with a high risk score. It contains an embedded URI pointing to 'https://soxebez.ru/aws?utm_term=how+to+make+a+house+for+your+pet+rock', which is likely the primary lure. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the detection suggest it's designed to redirect users to malicious content, potentially leading to phishing or further malware download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/aws?utm_term=how+to+make+a+house+for+your+pet+rock
    • http://mozobadijoba.medianewsonline.com/what_is_modern_greek_culture.pdf
    • http://fuxuxixigu.scienceontheweb.net/customs_law_manual_2020_16.pdf
    • http://gijemafovipa.iblogger.org/xosumimiperuguf.pdf
    • http://tometifo.getenjoyment.net/25475814241.pdf
    • http://penageli.getenjoyment.net/70096853420.pdf
    • http://welakeriduxu.22web.org/unitedhealthcare_community_plan_dental_phone_number.pdf
    • http://jedusajinud.mygamesonline.org/dafazenu.pdf
    • http://valupimabo.22web.org/16282033122.pdf
    • http://tobaliwono.mygamesonline.org/absorcion_de_la_luz.pdf
    • http://nowukusox.mypressonline.com/what_is_your_unique_student_identifier.pdf
    • http://xakaderinetatu.mygamesonline.org/xarikorekam.pdf
    • http://xokezuwadem.mygamesonline.org/zanewib.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6c9aa500-f8d9-42a6-b8a4-5b3c562bbfc3.filesusr.com/ugd/543886_5afeedf454d844a59dae5c51f71cdcbb.pdf?index=true
    • http://temewafin.rf.gd/15277282693.pdf
    • http://pomagupivedib.epizy.com/13996566729.pdf
    • http://gupemag.epizy.com/paperokefemenijulavuwisa.pdf
    • http://jilevatawew.epizy.com/mezevumovuxamazuviku.pdf
    • http://gumomexad.onlinewebshop.net/rookwood_catholic_cemetery_map.pdf
    • http://situwosase.myartsonline.com/nipitaxodepufozul.pdf
    • http://pukunoganisopa.epizy.com/kompres_file_ke_jpg.pdf
    • http://rofixalo.epizy.com/printable_letter_templates_for_cake_decorating.pdf
    • https://d5e9a058-cbdc-4968-ba72-30cdbf1e36a3.filesusr.com/ugd/9cfd0a_5e7a9880d68d413fac67e212102d9000.pdf?index=true
    • http://romepasuv.myartsonline.com/69436497191.pdf
    • http://vupaguriwedizid.atwebpages.com/970723590.pdf
    • https://e148473a-3d1a-46f8-b788-fbc1f5af68d4.filesusr.com/ugd/e1e70b_09a91387d1a549b1875984ea4cd63b00.pdf?index=true
    • http://kapetevik.epizy.com/appium_android_test.pdf
    • https://2ed821ec-8078-4e74-b11b-c5cec6a88262.filesusr.com/ugd/65e777_61fc2e4125ce449f9eb18f9d5b49f42c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f9e5.bin
e8261999fa9d3b31dae0daa2c57f6794dd81815e46cb5c61660a29c087f5a0d2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF9E5 5440 bytes
font_01_sfnt_off00010c54.bin
ffdc16c9af8e07cad215a768982b5dbb69f1beed37010d36b99fec334a181c9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C54 10480 bytes