Malicious PDF — malware analysis report

Static analysis result for SHA-256 71593d16bbcea4d2…

MALICIOUS

PDF

142.1 KB Created: 2021-04-10 00:02:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bf5de3952bb5b86cfe56153afafc7d9b SHA-1: b898be3ea7b1e9763c2b883c4c1460faa71febfb SHA-256: 71593d16bbcea4d2b1e1260c0ea94f521ee7e30dfb5495d53a995bf6b9ad0cfd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with the primary one being vilenefex.ru, which is flagged as suspicious. ClamAV detection and ML classification strongly indicate malicious intent. The document body, though heavily obfuscated, suggests a lure related to a 'summary' or 'form', aligning with phishing or malware delivery tactics. The presence of PDF_URI and EMBEDDED_URL heuristics further supports the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9959

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=after+virtue+summary+pdf
    • http://towufato.mywebcommunity.org/thailand_visa_on_arrival_form_2020_download.pdf
    • http://kajuzumanaz.sportsontheweb.net/80461556742.pdf
    • http://xafesuvorolivig.scienceontheweb.net/46965753368.pdf
    • https://cdn-cms.f-static.net/uploads/4368471/normal_601623e3274cc.pdf
    • https://cdn-cms.f-static.net/uploads/4449419/normal_6018f85a403e7.pdf
    • http://tipofeliluget.medianewsonline.com/renewable_and_efficient_electric_power_systems_solutions_manual.pdf
    • http://sagedix.medianewsonline.com/what_is_the_best_value_for_money_metal_detector.pdf
    • http://siwupezomejen.getenjoyment.net/clasificacion_de_la_administracion_publica_en_mexico.pdf
    • http://gatofupimekow.mywebcommunity.org/31599996325.pdf
    • http://fofiwafajelerax.sportsontheweb.net/evidence_based_education.pdf
    • https://cdn-cms.f-static.net/uploads/4465688/normal_6059f7c727ee7.pdf
    • https://cdn-cms.f-static.net/uploads/4380068/normal_601fa7cb1a5ad.pdf
    • http://vomidujoma.scienceontheweb.net/cgegis_table_july_2020.pdf
    • https://static.s123-cdn-static.com/uploads/4446782/normal_5ff1860f014ea.pdf
    • http://fajujefa.getenjoyment.net/27301279849.pdf
    • http://rebibedo.mywebcommunity.org/kikalusulawuzosevutufuw.pdf
    • http://baditunabupiru.mywebcommunity.org/blades_in_the_dark_heist_deck.pdf
    • http://mapugukabazewu.scienceontheweb.net/axis_bank_fd_interest_rates_today.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/bepukuba/garmin_vivosmart_4_user_manual.pdf
    • https://s3.amazonaws.com/kosamupim/caxton_legal_centre_annual_report.pdf
    • https://s3.amazonaws.com/jajoxulabojaso/oster_clipper_blade_sharpening_service.pdf
    • https://s3.amazonaws.com/setikizo/the_nightingale_movie_free.pdf
    • https://s3.amazonaws.com/juvetaso/what_is_a_learned_behavior_of_a_dog.pdf
    • https://s3.amazonaws.com/zulezov/badminton_league_game_for_pc.pdf
    • https://s3.amazonaws.com/radubozufiwo/cfaa_full_form.pdf
    • https://s3.amazonaws.com/fewifuwu/bodejeduzegoru.pdf
    • https://s3.amazonaws.com/rexogeguxosix/78676821882.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001f19c.bin
0d39556a5a4fe353db7e435eb874f6c4df3a34e7d47f83110db3b5ad31a6b230
pdf-font-stream PDF embedded font (sfnt) at offset 0x1F19C 5304 bytes
font_01_sfnt_off000203a3.bin
d7da70c346686a66c675311c84b030b64b5dbdef03dfcfdcc0fcca6ee6fa2062
pdf-font-stream PDF embedded font (sfnt) at offset 0x203A3 11020 bytes