Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c24e6626185f741…

MALICIOUS

PDF

81.6 KB Created: 2021-03-19 19:20:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e99d1381c9670a71cb8e97f465d9d105 SHA-1: 71eeccaf85874faec358591a3367d973fb696024 SHA-256: 6c24e6626185f7413d5a1f8e404874add1faa37207102d26a519a771f9a9a094
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an external URI pointing to 'nipisod.ru' which is likely part of the malicious download chain. The presence of a visual download button lure further supports a phishing or social engineering attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=jumanji+google+drive
    • https://cdn.sqhk.co/wopidaxiwuk/jugihhd/jikizibu.pdf
    • https://cdn.sqhk.co/kaxonavi/ibmegd0/netflix_party_chrome_extension_not_showing_up.pdf
    • http://muwazowezijowa.22web.org/measurement_of_length_physics_lab_answers.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fewunadupop/european_journal_of_operational_research_abs_ranking.pdf
    • https://s3.amazonaws.com/fofeguj/74754757437.pdf
    • https://s3.amazonaws.com/kobivimelelo/lowujo.pdf
    • https://uploads.strikinglycdn.com/files/79da4541-7923-4f59-9b45-cb38c29d33ec/tagibagozepobatez.pdf
    • https://uploads.strikinglycdn.com/files/b5038622-d85b-465c-bd65-6971435f3d1f/32642401037.pdf
    • https://s3.amazonaws.com/tedowafomaru/husqvarna_18_inch_445e_ii_gas_chainsaw.pdf
    • https://s3.amazonaws.com/sagotomagin/32117082800.pdf
    • http://nosaras.rf.gd/baby_shark_piano_notes.pdf
    • https://uploads.strikinglycdn.com/files/7c578887-ab06-4729-890a-3505f8f52d64/hound_of_the_baskervilles_chapter_11-15_summary.pdf
    • https://s3.amazonaws.com/wamatasamegu/aparatos_de_ortopedia_dental.pdf
    • https://s3.amazonaws.com/jivuxo/dopizogu.pdf
    • http://vovajixavago.epizy.com/nuwiwinasebizigunag.pdf
    • https://s3.amazonaws.com/pevarijidasalop/creative_writing_skills_and_techniques.pdf
    • http://kekunulu.epizy.com/25325654220.pdf
    • http://vejobewibibir.epizy.com/57548543712.pdf
    • https://uploads.strikinglycdn.com/files/e75531df-1961-48d2-8827-ee107aaba56d/youth_soccer_strength_training_program.pdf
    • https://s3.amazonaws.com/nokiva/58639401085.pdf
    • https://s3.amazonaws.com/vofadoloves/62412614643.pdf
    • https://uploads.strikinglycdn.com/files/383e28cd-da7e-40b2-adab-ade7f216452c/73290390144.pdf
    • https://s3.amazonaws.com/metubevozisul/washington_capitals_schedule_2017-_18.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103f7.bin
23f82c3cee593ce16b5b7df6f8e87da586478a4b8ebe047e9d7edf608bb73b0a
pdf-font-stream PDF embedded font (sfnt) at offset 0x103F7 5092 bytes
font_01_sfnt_off0001153a.bin
6bad6566ff17a52a75e78cf3b2b77ee2091022fa9ba506d34e47ab887a89de7e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1153A 10448 bytes