Malicious PDF — malware analysis report

Static analysis result for SHA-256 697d5933396f11c5…

MALICIOUS

PDF

67.8 KB Created: 2021-04-02 06:24:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a767ad11e3ec71497149631ea2ff705b SHA-1: 50b40114b6acd113a8f6adcdebc09454bd4f5894 SHA-256: 697d5933396f11c5bc69e4e8fd1d57d3fbc834994232cf71c2a6bdd58981ce48
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded URLs that lead to potentially malicious domains, as indicated by the ML classifier and ClamAV detection. The document body, though heavily obfuscated, contains text suggesting a lure related to 'gangster games'. The presence of embedded URLs and the overall detection by security tools strongly suggest this file is part of a phishing or malware distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/123?utm_term=gangster+games++dedomil.+net
    • https://cdn-cms.f-static.net/uploads/4446646/normal_60562ec6b2a5e.pdf
    • http://vadanunagirira.getenjoyment.net/depovoje.pdf
    • https://static.s123-cdn-static.com/uploads/4454682/normal_5fee3da5abbcc.pdf
    • https://cdn.sqhk.co/gapebeve/3GjjOig/personal_assistant_app_for_android_mobile.pdf
    • http://pilagapub.iblogger.org/suzavaperazulavu.pdf
    • https://cdn-cms.f-static.net/uploads/4377410/normal_6013d9bdcb0cb.pdf
    • http://bivoliku.mywebcommunity.org/fases_del_aprendizaje_basado_en_proyectos.pdf
    • http://gazedalepi.sportsontheweb.net/85428587512.pdf
    • https://static.s123-cdn-static.com/uploads/4376359/normal_5fc9afb5bb5f5.pdf
    • https://static.s123-cdn-static.com/uploads/4387698/normal_5fd0861280c16.pdf
    • https://cdn.sqhk.co/womilepeba/jgHjggg/hide_speaker_wire_lowes.pdf
    • https://static.s123-cdn-static.com/uploads/4501201/normal_6000fb4575297.pdf
    • https://cdn-cms.f-static.net/uploads/4425515/normal_6021a46f16cf8.pdf
    • https://cdn-cms.f-static.net/uploads/4458631/normal_60494b16a5811.pdf
    • http://vikunokanafigul.66ghz.com/gipumuwulolukoxuzuxemidu.pdf
    • https://static.s123-cdn-static.com/uploads/4496580/normal_60015fd95093f.pdf
    • https://cdn.sqhk.co/wiwuwigo/DRIgdji/codelite_compiler_settings.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/04dd50e5-c94d-41d4-8b4b-589aad01db38/golabikupijakakitaxuxetap.pdf
    • http://lowebabufi.rf.gd/suwazewapoxekezizaju.pdf
    • https://uploads.strikinglycdn.com/files/edbfa712-063c-42a4-a823-fd344bb96c0c/56529833994.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cc4e.bin
211060152c83b973b8b2379546eb27bc3d492460d0608917fcb3129cf76dc6f7
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC4E 5208 bytes
font_01_sfnt_off0000ddf5.bin
26d33a764e92309105ffb82c220f3f2f9c072a4e54166612124baacccb60a1f5
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDF5 10116 bytes