Malicious PDF — malware analysis report

Static analysis result for SHA-256 787fdb7e4e11ce94…

MALICIOUS

PDF

205.2 KB Created: 2021-03-30 14:23:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-22
MD5: 4ac98b549cb2678b2fbcdd71db3d6879 SHA-1: d219ebbe737de503eabe879cd050c5616d35ff43 SHA-256: 787fdb7e4e11ce94114cb2ba6f4eedbaaa2d50f7d66cda73ee8d8a8a026d8aa8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for an external URI pointing to a suspicious domain, which is also present in the document body. ClamAV and an ML classifier also flagged this PDF as malicious, specifically as a phishing trojan. No scripts were extracted, but the presence of a malicious URL suggests a phishing attempt to redirect the user to a compromised site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9937

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/strik?utm_term=what+does+traditional+korean+music+sound+like PDF link annotation
    • https://mujoganik.weebly.com/uploads/1/3/0/7/130776873/getolozoja.pdfIn PDF document text
    • https://bovimifukid.weebly.com/uploads/1/3/4/8/134882826/xibuxenodese.pdfIn PDF document text
    • https://nikotegonekis.weebly.com/uploads/1/3/4/6/134628666/10030527d0579fa.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://posopikepikan.rf.gd/fishing_rigs_for_brown_trout.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a0211d79-c072-4393-8e55-ecf9dc7f5a17/saul_alinsky_12_rules_for_radicals.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/80bf7e98-fa4f-45ee-91d6-31481c99c444/hp_5520_ink_cartridges_tesco.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/09c2547a-00a6-4b1d-b807-f6de60a7507a/digital_smart_board_price_in_nepal.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8e82f307-e91b-4f04-bcd0-29a0535c0764/star_wars_thrawn_treason_epub.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/69f33477-7c70-4ccd-a13c-890ceb27cd53/gapapaninu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ec58f162-7ac6-448d-afaf-d1cd90792fca/craftsman_table_saw_model_113_blade_guard.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d29be45f-5e03-40af-b816-aa90ec8b194e/mens_health_best_workout_videos.pdfIn PDF document text
    • http://monigadukuze.rf.gd/kuruvukiw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c2c4df1c-14b7-4e37-b549-22006f9fa991/14182683023.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8b9ad231-d6a8-4a11-84b4-44f720f5547a/download_film_divergent_sub_indo_free.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b0f7a0da-efb0-4875-b822-caf5bb57c90b/gukamimevebipunimemisoxat.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/02c4b66a-8719-4e80-b67d-9c37c37dbd11/gusibut.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1ccf926c-13cf-4442-9daf-99aaf0ce44f1/tidopiladinoxojivozenato.pdfIn PDF document text
    • http://robabaxagolelez.rf.gd/bardic_performance_5e.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002309e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2309E 64784 bytes
SHA-256: 31f9e8bb58cebd625325793d879f3d15b2ecd04c810d4f93b34cf2611dd94143
font_01_sfnt_off0002e9ef.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2E9EF 5256 bytes
SHA-256: 2f616a73e2fa141cc87d7e20d586361b3e1ab1464d0709b3ee945a32c8794f03
font_02_sfnt_off0002fbad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2FBAD 12708 bytes
SHA-256: a0afbeecd831814671ac7209fe3ff94846d428bc07b13f6e964986a11f076a3b