Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b27acb1ab631b03…

MALICIOUS

PDF

76.7 KB Created: 2021-03-06 03:56:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 64cfbe84459558bc1918a71b9acacef2 SHA-1: 5de645f94d11be3a3ec6994d1aa4bb371ab2a130 SHA-256: 6b27acb1ab631b036a40e5c56006cffc1e819709c8c5b24d66b6f62850cc0804
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, which is likely intended to redirect the user to a malicious site. The presence of multiple suspicious URLs further supports the phishing and malware distribution intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=monkey+business+name+origin
    • http://fredo.run/39817922859rh4ri.pdf
    • http://idealica-official.website/87759337837xtnbg.pdf
    • https://vesizolakaz.weebly.com/uploads/1/3/4/3/134333528/fb595.pdf
    • http://openplafond.xyz/domodivebupexead5n6.pdf
    • https://cdn-cms.f-static.net/uploads/4420752/normal_603009630147b.pdf
    • https://cdn-cms.f-static.net/uploads/4447467/normal_5fd26791b89ce.pdf
    • http://winoorama.site/tudofoxovuposulawifurijr68t.pdf
    • https://cdn-cms.f-static.net/uploads/4413468/normal_602f3749cc262.pdf
    • https://cdn-cms.f-static.net/uploads/4426972/normal_601973b1e07f2.pdf
    • http://evatopshop.xyz/ban_gayi_rikshawala_dj_songosjch.pdf
    • https://static.s123-cdn-static.com/uploads/4465543/normal_5ff70d0e6aedf.pdf
    • http://tiktoktop.design/xazagiji0av1.pdf
    • https://levapexufusetij.weebly.com/uploads/1/3/4/9/134904519/ce53f.pdf
    • https://bizonununifewe.weebly.com/uploads/1/3/4/7/134773553/zozexujuv_vakuw_jixekam_diwamu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jijari/tolakowujax.pdf
    • https://s3.amazonaws.com/lazesej/blade_230s_v2_for_sale.pdf
    • https://uploads.strikinglycdn.com/files/8a69120d-b14c-486f-925e-976bfb01e2f6/rujobifutovilirunudetumud.pdf
    • https://uploads.strikinglycdn.com/files/7a8cc7e7-9ee5-4106-a972-113dea07867a/dinafivoxitujuzibajob.pdf
    • https://uploads.strikinglycdn.com/files/17cf597a-7b2f-40a2-ba81-fc901ced69aa/30933946878.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f030.bin
dd1738d5257f57829d3453a75c11ebbd787576947d64745a04b0f57bebac7c1c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF030 5284 bytes
font_01_sfnt_off0001022e.bin
efc1c093b5b915fdb9a13804ddca84c78fccd48ac8f234903f7d82104e437f17
pdf-font-stream PDF embedded font (sfnt) at offset 0x1022E 10552 bytes