Malicious PDF — malware analysis report

Static analysis result for SHA-256 67cc62779ef14d05…

MALICIOUS

PDF

73.6 KB Created: 2021-03-18 06:12:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4f2615fbfee5fe354638321e7cb3c9b SHA-1: 22abefa8c6105b1d08c5b7f4011b160231b5eb82 SHA-256: 67cc62779ef14d053ef26b0c16c7b6ce25606ccd3b29c57002b99af76c5b052a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, indicating a high likelihood of malicious intent. The embedded URLs, such as 'https://zajinet.ru/strik?utm_term=a+series+of+unfortunate+events+pc+game+free+download', suggest a phishing or social engineering lure, likely attempting to trick users into downloading malware disguised as legitimate software. No scripts were extracted, but the PDF structure and embedded URIs are sufficient indicators of a phishing attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=a+series+of+unfortunate+events+pc+game+free+download
    • https://static.s123-cdn-static.com/uploads/4453888/normal_5fcceefc9a1fe.pdf
    • http://mexicotop.xyz/singular_and_plural_nouns_powerpoint_presentationfk206.pdf
    • https://cdn.sqhk.co/fuluzagile/fPZjdjj/god_simulator_games_free_online.pdf
    • https://cdn-cms.f-static.net/uploads/4421629/normal_603c683393642.pdf
    • https://cdn-cms.f-static.net/uploads/4446944/normal_603c7655c09d8.pdf
    • https://cdn-cms.f-static.net/uploads/4418565/normal_603ed425d6f04.pdf
    • http://servempieza.site/94010877483p2g7g.pdf
    • https://cdn.sqhk.co/vixuzemabad/fjiVc9U/combat_duty_modern_strike_fps_mod.pdf
    • https://cdn-cms.f-static.net/uploads/4375517/normal_604123c69084a.pdf
    • https://cdn-cms.f-static.net/uploads/4457000/normal_603fba130a2b4.pdf
    • http://idealsit.fun/the_second_act_of_uniformitynawhw.pdf
    • http://eurofamily.pro/linegezotegn329n.pdf
    • https://static.s123-cdn-static.com/uploads/4453720/normal_5fcb6685cce1d.pdf
    • http://nncucuucuc.space/zojev13c45.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kitakilesa/loluk.pdf
    • https://uploads.strikinglycdn.com/files/35fa14d8-1f6c-4290-847b-83d2afa4de05/23028102742.pdf
    • https://s3.amazonaws.com/mokixetat/bad_blood_series.pdf
    • https://s3.amazonaws.com/zarevizebi/puxozoxovififasozub.pdf
    • https://uploads.strikinglycdn.com/files/4ceabd82-b9d3-44a7-bbf0-4c838aef859c/69233314222.pdf
    • https://s3.amazonaws.com/mokuwanibof/jurnal_ancylostoma_caninum.pdf
    • https://s3.amazonaws.com/gafedupeba/33790133998.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dfcb.bin
df6980269443ab74669144a0eb21f54bbe97511d8196b4055f6747d0ee50d6cd
pdf-font-stream PDF embedded font (sfnt) at offset 0xDFCB 5616 bytes
font_01_sfnt_off0000f2e5.bin
e776140bb02cddd99b6572503eee0c84a6b1c80633b58a4f8afbc9e256e4ddb1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF2E5 10508 bytes