Malicious PDF — malware analysis report

Static analysis result for SHA-256 740b1e7038a983a4…

MALICIOUS

PDF

106.6 KB Created: 2021-03-18 23:14:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: edc22ab297f9e31f2e0b384d58efd07b SHA-1: 3643a1c59e7e8d6aa8366893dedcb021df4d5142 SHA-256: 740b1e7038a983a40cdf8fce8893eed1e32b52fde2ac6baebb1aba82e5b82351
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

This PDF document was flagged as malicious by ClamAV and an ML classifier. It uses a password-protected-archive lure. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=descargar+una+serie+de+eventos+desafortunados+pdf PDF link annotation
    • https://cdn.sqhk.co/tupizurelir/ahdjijf/53693374082.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4506131/normal_6039c317b2dcc.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4421468/normal_5fccd4f348261.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4504870/normal_5fedd745a085c.pdfIn PDF document text
    • https://cdn.sqhk.co/ladetozuxi/jdYicmZ/ice_cream_cone_making_project_report.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408464/normal_6031b51851af5.pdfIn PDF document text
    • https://cdn.sqhk.co/pategazikiw/hcifGgc/risosagur.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4485930/normal_5fd7a1653ae40.pdfIn PDF document text
    • https://cdn.sqhk.co/potiribuwuf/ehfNijt/microsoft_defender_2020_review.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4409239/normal_5ffea3ca1eb0c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7cc3012-03c5-4739-9a71-85d5c2149499/how_to_be_a_good_student_athlete_in_high_school.pdfIn PDF document text
    • https://e691ad07-92dc-45fa-af10-8929b4045ede.filesusr.com/ugd/87b9a8_fbfb5ff82c1f4993acd96a69d23b81e2.pdf?index=trueIn PDF document text
    • https://d4996ccb-aecf-47c4-aab6-3c4fe022e1b7.filesusr.com/ugd/b7ed05_d9f08ccb34f7409c8484eccc2dd8c226.pdf?index=trueIn PDF document text
    • https://abee6ad4-cf47-459a-954e-22b9b9bb30ad.filesusr.com/ugd/4bdc6d_1df734b908744213b31ce2e81943ab5c.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/5e7a827f-bc80-4abd-a17b-6083066fdce4/wd_my_cloud_ex2_ultra_technische_daten.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f0e69dd8-c0f1-4845-93a7-814458a64a74/35898402259.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4e1f7043-982c-45dd-a9cd-fa70f59d8e73/geotechnical_engineering_principles_and_practices_2nd_edition_coduto.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0c524649-9732-4c29-9f8d-5177cf803147/dd_3.5_rules.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001381f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1381F 4388 bytes
SHA-256: c1e1f91717ea2940d50c1920641c75b9ab4b833a5004b84e821e7c7f2ca42fd5
font_01_sfnt_off0001477d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1477D 5348 bytes
SHA-256: 4dc71f4852c7b2e0a66604367ac6d6795bfc2964c96db227e71a49357d8126e7
font_02_sfnt_off000159d0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x159D0 14056 bytes
SHA-256: 4259a893e044f9a22b1949d90f5be7468cf6b1530d63fe25c4c8266a77d7e5ce
font_03_sfnt_off0001856f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1856F 16204 bytes
SHA-256: e93acd332f5893643511f4cefd38969ad5c744ad1b08842a788b6be7d277dd15