Malicious PDF — malware analysis report

Static analysis result for SHA-256 75768a93105acd9a…

MALICIOUS

PDF

71.3 KB Created: 2021-05-29 03:49:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 8678ca476d35d0e8eb6e71ad002534c2 SHA-1: 95cd2246e53cc04cf2fbcf9cc9328c01bc9a539f SHA-256: 75768a93105acd9afd4dbbf37874ec9fbf895a8c8cc3e232383ba129be707846
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=best+buy+geek+squad+phone+number+please PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4464070/normal_600ded4ba7ee9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4493876/normal_60463eaf4a184.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413375/normal_6067801627617.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4465705/normal_60261b04c691b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391898/normal_60272f82857ad.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4482020/normal_60aff5e824f15.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389820/normal_6025f8c8195c6.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4366947/normal_5feb16b5cec2d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4425929/normal_60698bb063c92.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4377704/normal_6026bd7963d32.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/77e4caea-559f-4a25-bce1-78c84c70910b/tabla_de_radicales_de_alcanos_y_cicloalcanos_con_nombre_y_formula.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4ae8e6ca-a5f1-4c04-be6e-cafddfd1b4ed/tomufolelufiwivebokupol.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0f205b03-6707-49ca-b8ac-def6fc122c97/how_long_is_a_mechanical_pencil_in_inches.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/333d336d-e892-4ba7-bd4a-198d3fcafaa2/interior_designer_salary_canada_2018.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d775cbd9-2bdd-4481-a696-04503b1c06de/what_does_the_bus_ticket_represent_in_a_streetcar_named_desire.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f665c88a-7bdc-455f-9f80-4ab43c638ee3/whered_you_go_bernadette_review_ebert.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5b22c689-98a0-40db-a578-8369940d6296/how_to_clean_lg_direct_drive_washing_machine_filter.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a5bf52a2-f2f0-4f1e-8d4d-db01741ba68c/wendys_restaurant_employee_handbook.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/96475d3b-6a6e-4f1a-a00f-4474ba260c28/13505437365.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c961f178-6683-447e-b450-535f11d6de70/football_drills_for_four_year_olds.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dfb90318-9e9b-4c36-8bf5-b511b21eadac/xujakanoka.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3bd3222f-babd-4af2-90a7-67d6162a1f33/jbl_eon_615_price_in_philippines.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc9f63af-2844-4156-853b-620187bbb795/21490554982.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/314df2fe-57fc-46b8-91b6-745bde3cb8a8/nomebemidedugiguzi.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000db7e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDB7E 5852 bytes
SHA-256: 5f90d81a5aa1fd7544765944390aecc0a9c4fe2a284618c809a3631d620d9a1e
font_01_sfnt_off0000ef3e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF3E 9216 bytes
SHA-256: 4609a44011e1d7decf6708421708832595e7b55b01459b7e94655c7be5671181