Malicious PDF — malware analysis report

Static analysis result for SHA-256 69da1c74cb53d0ec…

MALICIOUS

PDF

147.0 KB Created: 2021-06-14 04:53:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0787ca9651410e38ed6ffcc18c33241a SHA-1: de9c0e36dbc61c567296093833fd524bbf29e258 SHA-256: 69da1c74cb53d0ec7bbbd8f97cc4a2a9e0251156c938f638db203e308b1ff102
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that, when visited, likely leads to further malicious activity. The document body, though heavily obfuscated, contains text related to a TV show, suggesting a social engineering lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://wastran.ru/pbw?utm_term=my+love+from+the+star+tagalog+episode+1
    • https://cdn-cms.f-static.net/uploads/4420597/normal_60206525308fd.pdf
    • https://cdn-cms.f-static.net/uploads/4367297/normal_6056f3019b60b.pdf
    • https://static.s123-cdn-static.com/uploads/4459054/normal_6001d2aa4b139.pdf
    • https://zogabugopevaluz.weebly.com/uploads/1/3/0/8/130814784/c6c18b30bbd4575.pdf
    • https://cdn-cms.f-static.net/uploads/4366028/normal_602d33cd92c59.pdf
    • https://xoravali.weebly.com/uploads/1/3/0/7/130775395/zikipelelidekadi.pdf
    • https://disamaro.weebly.com/uploads/1/3/4/6/134697064/e3d04a7020.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • https://uploads.strikinglycdn.com/files/8986caac-d28b-49ee-b90a-fc38bf3234b6/moko_keyboard_not_working_surface_pro_4.pdf
    • https://uploads.strikinglycdn.com/files/cb21e78f-e55c-4a3a-b066-de3ce0ac95f2/carry_on_baggage_weight_limit_air_india.pdf
    • https://uploads.strikinglycdn.com/files/f52ecf7f-e259-4367-bdb5-7c46be870030/dokarewaxamobixatorezawaj.pdf
    • https://uploads.strikinglycdn.com/files/9724508e-96a6-4458-808b-2df03defaca7/83907195855.pdf
    • https://uploads.strikinglycdn.com/files/fa051e7f-2ac6-42de-a7f2-7cc371956dd3/different_forms_of_fatigue.pdf
    • https://uploads.strikinglycdn.com/files/4dcef17a-58e9-4f52-bbdc-d60014c8dc33/gameboy_advance_sp_ags_101_screen_replacement.pdf
    • https://uploads.strikinglycdn.com/files/bccb365d-c5fc-4e59-b8d8-a08ad6cecf7d/96852945711.pdf
    • https://uploads.strikinglycdn.com/files/2a9de2ce-d809-485d-a775-72e1eede6dd0/19388457050.pdf
    • https://uploads.strikinglycdn.com/files/cbb92507-4281-467a-a20a-89fd5d42fdd3/go_math_grade_4_teacher_edition_answers_chapter_11.pdf
    • https://uploads.strikinglycdn.com/files/97b6006a-bd65-446c-8875-52cb6d5512ac/what_are_the_three_parts_of_the_nicene_creed.pdf
    • https://uploads.strikinglycdn.com/files/596fedcb-2c47-4754-a498-b8a6885e0bd7/mtd_lawn_tractor_parts_near_me.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019315.bin
c2acd5d503f9f62a829df7cc8b291e3828c1613233a97ba138eceb4ff6cd9a2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x19315 29540 bytes
font_01_sfnt_off0001e5de.bin
3c5cec77c16e0739122ff70d06defd89f092b1adf240c8f48d6b57eda7cdc0b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E5DE 5672 bytes
font_02_sfnt_off0001f916.bin
2d41beb357ea8927353792883bf7571e67f9bc23587274f461ca1ab87e88e530
pdf-font-stream PDF embedded font (sfnt) at offset 0x1F916 9000 bytes
font_03_sfnt_off000211ad.bin
e97bb981bf0ee031d7fcf9e9b9acc3be4c5cf7483f73c76e5b0fdcdd16dc8054
pdf-font-stream PDF embedded font (sfnt) at offset 0x211AD 12472 bytes