Malicious PDF — malware analysis report

Static analysis result for SHA-256 71e6a47eedc130f0…

MALICIOUS

PDF

89.2 KB Created: 2020-12-02 11:41:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 317ee7a98b95dd1970d30be0937c01c0 SHA-1: b8324e940af33d01513608e8ce096d4cd6955026 SHA-256: 71e6a47eedc130f0412fb03efb9415025abb5f19aaea98b1e20866560bac91fa
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/strik?utm_term=free+roblox+gift+card+codes+2020+unused+no+human+verification PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4383918/normal_5f95ed3749237.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470960/normal_5fc068749c332.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4388416/normal_5fc0a0d1ec9fc.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370268/normal_5fa89814ee9e7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417531/normal_5f96522f2308f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470232/normal_5fa496533e473.pdfIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/05744f95-b44e-48b4-94fa-0b388bf4b85b/lenguaje_y_tipos_de_lenguaje.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/df5289b2-a48e-4506-b00d-501ba22a0d03/71975772126.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f75ae627-eb92-488b-8eb1-14449040bf46/stump_root_device_is_patched.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3615541b-fa2d-435d-be6e-0ee9ae9705e9/wight_dd_beyond.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ae1fd79f-3b98-4e32-a4bd-d90625901f94/83470736349.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a0b9883-eb83-4f1e-8064-ed4b4d3cf825/phillip_glass_buys_a_loaf_of_bread.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cfa19bc7-066b-4724-b5b3-e95c2f51c5c0/kaxan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ea36a5b2-a029-4f22-8974-4ba51b5d3be6/plot_diagram_worksheet.pdfIn PDF document text
    • https://static1.squarespace.com/static/5fc526b588c99b6d37c2ed9a/t/5fc713e0a3696915e21cea35/1606882275590/funny_videos_of_dogs_and_cats_talking.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000ee34.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xEE34 14024 bytes
SHA-256: 6a01f22c68caa210796e12d38b6e5911197d1d82697aab7dfbd7be017cf7c42b
font_00_sfnt_off0000da22.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDA22 5932 bytes
SHA-256: a57210ae95bf76de80f79fdf5b1e5d91942979e2143d9d5203280893f3c51900
font_02_sfnt_off000115b8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x115B8 2092 bytes
SHA-256: 6e5de5c6bcb7fdd8c5ca0d25823a8f80e6c764803c1b732dbc9c425a5c0f8ea5
font_03_sfnt_off00011f5e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11F5E 11124 bytes
SHA-256: 99fd2cd131b32ffa7a3ab7905a4c314257f0b9047791c0392ba5ef481ffacc07
font_04_sfnt_off0001457e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1457E 6068 bytes
SHA-256: 4b45f33c909d1de4119f908b2e4eeec8b51571bcf8b126b8fe9c8b95bec6d9c2