Malicious PDF — malware analysis report

Static analysis result for SHA-256 6f8750fbbf004b36…

MALICIOUS

PDF

75.4 KB Created: 2021-03-20 00:31:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6500b4be2e576aa4cee189204d6c949c SHA-1: 20b116fd9ef4dba690b03e5c377b4ed930d3a3b0 SHA-256: 6f8750fbbf004b363d170675864031738fd74f02f7fa08d4ef45e0cec9dca777
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains an embedded URL that directs users to a website promising free cheats for 'Seven Knights'. This is a common social engineering tactic used in phishing campaigns to trick users into visiting malicious sites. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/wix?keyword=seven+knights+cheats+for+free
    • https://cdn.sqhk.co/naludibeg/ebjfOBa/best_free_multiplayer_shooter_games_on_steam.pdf
    • https://cdn.sqhk.co/dewufidabo/enBoVOt/92344494198.pdf
    • https://cdn.sqhk.co/fokofike/1hah9gj/rujugevixipodinesazenanex.pdf
    • https://cdn.sqhk.co/kajutizikodu/ib2NP4g/kim_kardashian_hollywood_hack_no_human_verification_2020.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/gezizefefififa/arduino_mega_2560_manual_espaol.pdf
    • http://tavupikegoseri.epizy.com/68677792091.pdf
    • https://s3.amazonaws.com/savukojubusum/lizojut.pdf
    • http://difugarulid.epizy.com/cha_cha_slide_remix.pdf
    • http://nerepigov.rf.gd/49991997439.pdf
    • http://vatasinunevuto.epizy.com/newspaper_advert_template_psd.pdf
    • https://s3.amazonaws.com/tesotiwapax/how_to_reset_carrier_furnace.pdf
    • https://86a9da1b-0b57-4b35-a77a-523886b904cd.filesusr.com/ugd/0d9a50_5dffec892ba64d91958240ea33834cb9.pdf?index=true
    • http://zonezeg.rf.gd/1079872756.pdf
    • http://xipibevamelun.rf.gd/lenida.pdf
    • https://s3.amazonaws.com/pisedij/pewisinojamebomilasibori.pdf
    • https://b5d51143-f34a-4a4f-9265-6917490cb775.filesusr.com/ugd/9f69bd_f3e29c50b6d64e9d96e9e00dc91a6a5c.pdf?index=true
    • https://uploads.strikinglycdn.com/files/9434bb9c-8fb4-43f6-8e69-a85219fa96e2/envirotemp_water_heater_thermal_switch.pdf
    • https://uploads.strikinglycdn.com/files/e32b65c9-5932-4939-a406-8b83127049d1/toshiba_dp5022c-sdm_user_manual.pdf
    • https://uploads.strikinglycdn.com/files/95602f05-4381-425b-8b92-6f89af14233a/why_does_my_printer_randomly_turn_on.pdf
    • https://uploads.strikinglycdn.com/files/eeb18417-f798-4b59-b260-edab8566084c/48484524704.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da78.bin
c39a768b31511df1ddcc9394ea5f881029e6b7fe5343a5133ad534f65ccdf756
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA78 5124 bytes
font_01_sfnt_off0000ebe1.bin
01675bb7591bb057e0fcdec2b346d526b73c4ec8a281f2aa8653c7bba0250ead
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBE1 11352 bytes
font_02_sfnt_off000111b2.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x111B2 4324 bytes