Malicious PDF — malware analysis report

Static analysis result for SHA-256 68c27634ab7e59fe…

MALICIOUS

PDF

83.2 KB Created: 2021-03-20 21:45:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8e0c0b76b6bb9c6a3d5fb1b0d549a9d7 SHA-1: db77bb3174ed1055d4a77d9bec0119703d6fbaa7 SHA-256: 68c27634ab7e59fe013a28febc11850ffc7585edf148e452a0076efeb68507e9
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating the presence of external URIs and command execution tokens within the document text. The primary malicious URL, https://bologen.ru/strik?utm_term=best+dc+comics+to+read+2020, is likely used to deliver a secondary payload or conduct phishing. No scripts were extracted, but the PDF structure and heuristics suggest an attempt to exploit user trust.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=best+dc+comics+to+read+2020
    • http://fonagifegelu.iblogger.org/amigas_y_rivales_el_feo_transformacion.pdf
    • http://pekuxareja.22web.org/30734745500.pdf
    • http://bitejodimoni.iblogger.org/11940805505.pdf
    • http://tatuxuvoziparu.mywebcommunity.org/how_to_increase_height_by_exercise.pdf
    • http://tifoxikutawe.sportsontheweb.net/26604383866.pdf
    • http://zugunef.22web.org/which_detergent_is_best_for_washing_machine_in_india.pdf
    • http://notumaxesi.epizy
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gedexim/aiha_adalah.pdf
    • http://wivovazu.epizy.com/harry_potter_hogwarts_mystery_merula_duel_guide.pdf
    • http://siwemoxoxawevuv.atwebpages.com/amortizacion_financiera.pdf
    • http://wosaxadef.rf.gd/what_are_the_3_principles_of_experimental_design.pdf
    • https://s3.amazonaws.com/mijumomub/android_local_broadcast_receiver_example.pdf
    • http://lojupodinitaxug.epizy.com/vanirotenelosorofiwugun.pdf
    • https://s3.amazonaws.com/dojivewobasuval/how_to_make_your_child_have_a_photographic_memory.pdf
    • https://uploads.strikinglycdn.com/files/fc44b712-d630-4105-a80a-e1d324e3a947/how_to_use_a_curling_iron_on_very_short_hair.pdf
    • http://notumaxesi.epizy.com/birkat_hamazon.pdf
    • http://xuxamasisovuku.epizy.com/what_is_restriction_2_on_a_drivers_license.pdf
    • http://diribiboturo.epizy.com/boy_scout_uniform_guide_sash.pdf
    • http://sazasewugekupej.onlinewebshop.net/mtd_lawn_mower_carburetor.pdf
    • http://maxefaronuxugur.epizy.com/55175813039.pdf
    • https://s3.amazonaws.com/sivanira/44366476846.pdf
    • http://zorijefugixor.atwebpages.com/boruwuletuvevojotefa.pdf
    • https://s3.amazonaws.com/gidibesuxi/zusoriv.pdf
    • https://uploads.strikinglycdn.com/files/fd8896ef-3b06-46ff-bc8c-bc7a2397f4c0/entwined_in_finding_you_one_day.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010674.bin
8c67226758a07ed1cb9ae3db9df9c04b7993e93749b736f339dc2220e6aa521c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10674 5376 bytes
font_01_sfnt_off000118a4.bin
69af09442b4eb3e6135e0a71453ead002211b1c039621b39088f1e0e3469ef2c
pdf-font-stream PDF embedded font (sfnt) at offset 0x118A4 11284 bytes