Malicious PDF — malware analysis report

Static analysis result for SHA-256 686f1c5c72889c62…

MALICIOUS

PDF

75.7 KB Created: 2021-04-29 01:46:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3ac6c8d15ed72503198e516292f3903c SHA-1: 20edfa0056ee3ba74b2b4a8c630625dffd47d6ef SHA-256: 686f1c5c72889c62502d2db30505d7e57ce40f7bed3a516f83817f1657e1851d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a lure related to bruising, directing the user to a suspicious URL. ML classification and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=que+es+cuando+aparecen+moretones+en+el+cuerpo
    • https://cdn-cms.f-static.net/uploads/4389085/normal_604f7a4a2c15c.pdf
    • http://fesurowejo.mywebcommunity.org/zogurogijuwezafafesoz.pdf
    • http://jetinaxisodew.mypressonline.com/42382343893.pdf
    • http://kigaruzolalo.mypressonline.com/47195881234.pdf
    • https://cdn-cms.f-static.net/uploads/4445331/normal_600bfe896b64d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://desejole.myartsonline.com/cystic_fibrosis_causes.pdf
    • https://s3.amazonaws.com/wixanarer/access-_control-_allow-_origin_ionic_3_android.pdf
    • https://uploads.strikinglycdn.com/files/4b68ac98-969c-461b-9f9b-8dd3eced2951/singer_touch_and_sew_600e_maintenance.pdf
    • https://s3.amazonaws.com/vuzotisenixava/do_pianos_appreciate_in_value.pdf
    • http://tuminexozuvino.atwebpages.com/banking_awareness_book_by_disha_publication.pdf
    • https://s3.amazonaws.com/nefagolom/runazodof.pdf
    • https://s3.amazonaws.com/jolunenafobuw/kiteworks_administration_guide.pdf
    • https://ad9e3d1f-bb22-46ca-892e-b6aa3325a756.filesusr.com/ugd/837d34_fd6c0d7f032f45b99da38121bcbe8713.pdf?index=true
    • https://uploads.strikinglycdn.com/files/bce2e554-01ef-4900-a7b1-2f39614a9643/delta_sigma_theta_sisterhood_quotes.pdf
    • https://uploads.strikinglycdn.com/files/8a09c513-a66b-4719-bf20-aa590038c72b/how_can_i_eat_2600_calories_a_day.pdf
    • https://uploads.strikinglycdn.com/files/28ba54d9-5e3f-4f0b-94a9-b6ae2b18c71c/69970457883.pdf
    • https://uploads.strikinglycdn.com/files/b272b6ab-2cd1-4cf2-b1de-f03878091dcd/93982898457.pdf
    • https://109d6476-c6f4-4eee-b84c-907698fb4207.filesusr.com/ugd/0d7ebf_48f70c8a2a744358970f00b740d744ea.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8dc.bin
202c641e14cbc01f03a94db1bd90dfd83c074330192776c140d821311478838b
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8DC 5280 bytes
font_01_sfnt_off0000fab9.bin
21fa2b81a718790324b7e5e898e607685f451417f64940174983654848830ce1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAB9 11296 bytes