Malicious PDF — malware analysis report

Static analysis result for SHA-256 7749f2f7a97f4775…

MALICIOUS

PDF

75.7 KB Created: 2021-03-07 04:54:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 041cd02689e9df19beb3153478a8150b SHA-1: 46fcfb6b28904d8e751bd1fd26d353d2b6274ace SHA-256: 7749f2f7a97f47758b317c25b267df2e985d9d96b8cb749b5c707dadd91d650f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that appears to be a lure, disguised as a search result. No scripts were extracted, but the presence of an external URI and the high confidence detection suggest a phishing attempt designed to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/aws?utm_term=what+colors+are+blue+green+and+purple PDF link annotation
    • http://bubutun.iblogger.org/what_was_the_magna_carta_easy_definition.pdfIn PDF document text
    • http://dabuzasomadote.22web.org/when_christianity_start.pdfIn PDF document text
    • http://tefuvawilutir.mypressonline.com/vegugatusigizamexa.pdfIn PDF document text
    • http://mapotilij.mygamesonline.org/binomial_theorem_expansion_worksheet.pdfIn PDF document text
    • http://vowitufafuzebil.scienceontheweb.net/musuza.pdfIn PDF document text
    • http://komaxinatobofe.medianewsonline.com/8189497479.pdfIn PDF document text
    • http://zakapanu.iblogger.org/1613320241.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • http://jafufalabo.rf.gd/word_formatting_symbols_table.pdfIn PDF document text
    • https://s3.amazonaws.com/mudurixo/is_a_nissan_frontier_reliable.pdfIn PDF document text
    • http://wokoziguroron.rf.gd/24857232133.pdfIn PDF document text
    • https://s3.amazonaws.com/tonemakopinibem/psychology_11th_edition_myers.pdfIn PDF document text
    • http://kolenexe.epizy.com/gevemufaxeze.pdfIn PDF document text
    • https://s3.amazonaws.com/luropi/68811625325.pdfIn PDF document text
    • http://farujage.epizy.com/can_depression_cause_weight_gain_yahoo_answers.pdfIn PDF document text
    • http://bufijonewufo.onlinewebshop.net/49747016334.pdfIn PDF document text
    • https://s3.amazonaws.com/desenaz/ultrasound_scan_report_boy.pdfIn PDF document text
    • http://nejesezape.myartsonline.com/rcbs_reloading_dies_for_5.56.pdfIn PDF document text
    • https://s3.amazonaws.com/meludav/43956170639.pdfIn PDF document text
    • http://vupaguriwedizid.atwebpages.com/cant_see_shortcuts_on_desktop_windows_10.pdfIn PDF document text
    • http://bopunuzas.rf.gd/61298391559.pdfIn PDF document text
    • http://wasalesex.epizy.com/cgp_a_level_biology_exam_practice_workbook_answers.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc20.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC20 5324 bytes
SHA-256: 23fda4dc53e18b782d1ac4d9b5bf60ff3ae08b36cc92582520d8ce27f6a57f2c
font_01_sfnt_off0000ee2c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE2C 10636 bytes
SHA-256: f763835b15ae1bb0b17ffd0b8985570660b2fed8f7d5d39a56e64f6330b72cdd
font_02_sfnt_off0001128c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1128C 4324 bytes
SHA-256: 1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e