Malicious PDF — malware analysis report

Static analysis result for SHA-256 e549a3373928ee66…

MALICIOUS

PDF

247.2 KB Created: 2022-04-13 16:02:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 5.11.3)
MD5: baafeacb496a9d052535973e6c12b2de SHA-1: 94916725a35d1fbe19b73b60d497cd77264ccb27 SHA-256: e549a3373928ee66e91dd34ef5ceae7bb3fa49b1b604ab5c850c425d36b7d96c
106 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a malicious PDF detected by ClamAV and an ML classifier. It contains multiple embedded URIs, with the primary one being https://lazav.co.za/XSRYdR1H?utm_term=adobe+xd+tablet+template, likely leading to a phishing or malware download site. The PDF structure itself is also flagged for duplicate object bodies, indicating potential obfuscation or malformation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7707

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lazav.co.za/XSRYdR1H?utm_term=adobe+xd+tablet+template
    • https://patalilax.weebly.com/uploads/1/4/1/3/141344249/314d67c3ee7d9.pdf
    • https://ditugapagijesap.weebly.com/uploads/1/3/4/6/134651304/1119983.pdf
    • http://geofer.eu/userfiles/files/57090490182.pdf
    • https://disemorabegelam.weebly.com/uploads/1/3/1/3/131383982/2797777.pdf
    • https://lezotaxodad.weebly.com/uploads/1/3/4/4/134432483/af842.pdf
    • http://ahjygjg.com/upload_fck/file/2022-4-7/20220407095315449530.pdf
    • https://gukufevekexuse.weebly.com/uploads/1/3/5/3/135305262/tuxeruzubuwow-vibejimebisat-sarimabemub-pevasiw.pdf
    • https://dudakodut.weebly.com/uploads/1/3/4/4/134497067/garotoja-sotopobepam.pdf
    • https://kakadaten.weebly.com/uploads/1/3/0/9/130969907/7894629.pdf
    • https://tusaluzope.weebly.com/uploads/1/3/4/3/134374665/rojogijabikofeduzag.pdf
    • https://gupijevud.weebly.com/uploads/1/3/1/4/131407369/fuwime-nagep.pdf
    • https://temoxemotedi.weebly.com/uploads/1/3/4/5/134599163/xevojobarafup.pdf
    • https://weranatowo.weebly.com/uploads/1/3/1/4/131408071/cfcc2c0ff.pdf
    • https://nawogixabejuj.weebly.com/uploads/1/3/4/6/134617161/cce111b951b8.pdf
    • https://rogubofiduga.weebly.com/uploads/1/3/1/0/131069879/1050303.pdf
    • https://xasigevas.weebly.com/uploads/1/3/4/5/134595911/4280763.pdf
    • https://juromavunux.weebly.com/uploads/1/3/0/7/130776553/2568498.pdf
    • http://csc0311.com/userfiles/file/20220410080053_9v423l.pdf
    • https://radofagomomixa.weebly.com/uploads/1/3/4/1/134132329/2323513.pdf
    • https://mellorymotors.ru/admin/ckfinder/userfiles/files/41828991235.pdf
    • https://volorizog.weebly.com/uploads/1/3/1/0/131070051/2f3f76de.pdf
    • https://wulonuvesiga.weebly.com/uploads/1/3/4/3/134362584/goxixukutebakadepi.pdf
    • https://tizitumobupo.weebly.com/uploads/1/3/4/9/134904485/6a9b0.pdf
    • https://inmaabiladi.com/userfiles/files/63949060027.pdf
    • https://vuzigalami.weebly.com/uploads/1/3/5/9/135960382/4135407.pdf
    • https://zixotojene.weebly.com/uploads/1/3/4/3/134315054/wedama.pdf
    • https://terusabul.weebly.com/uploads/1/3/4/7/134702655/zimediwasugobeladig.pdf
    • https://fozapiko.weebly.com/uploads/1/3/0/9/130968993/sebizufoladaw-pamipegigimeku.pdf
    • https://wfca-czech.cz/temp/userfiles/files/40798375430.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00036f2c.bin
9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x36F2C 16792 bytes
font_01_sfnt_off00038743.bin
eb49cb8c85aff7c7eebf95555c1b424246b61eae569ad55a707bc50fbf05e6f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x38743 10312 bytes
font_02_sfnt_off00039e54.bin
c2ae35f1f5a7418fed135f1684754dfebf3fa5d6a59fce81c32d4087303bcc3b
pdf-font-stream PDF embedded font (sfnt) at offset 0x39E54 18120 bytes