Malicious PDF — malware analysis report

Static analysis result for SHA-256 78bc69714fe67723…

MALICIOUS

PDF

82.6 KB Created: 2021-03-19 21:12:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2aff57858779127262531e39509e80dc SHA-1: 704ff77b02d3d2ce124985bff00dbcad369e6d77 SHA-256: 78bc69714fe67723e644bdc1f5ab42523567dfcc6e4a5ec711da1471e0cfcb14
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that directs users to a suspicious domain, disguised as a resource for IELTS general writing topics. This URL is likely intended to lead the user to a phishing or malware distribution site. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=writing+topics+for+ielts+general+pdf
    • https://static.s123-cdn-static.com/uploads/4459796/normal_5fe03ebe2266b.pdf
    • https://cdn-cms.f-static.net/uploads/4384851/normal_60483d70150b3.pdf
    • http://wusator.mygamesonline.org/free_asvab_study_guide_2020.pdf
    • https://static.s123-cdn-static.com/uploads/4385231/normal_5ff28e50e574b.pdf
    • https://cdn-cms.f-static.net/uploads/4470218/normal_604db2afde44d.pdf
    • https://cdn-cms.f-static.net/uploads/4382773/normal_602a111115875.pdf
    • https://cdn-cms.f-static.net/uploads/4491152/normal_6033ea1562447.pdf
    • http://suwefazimim.medianewsonline.com/bugubuti.pdf
    • https://cdn-cms.f-static.net/uploads/4389384/normal_5fd2ff73da7d7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://c63ca81c-6df4-4ec3-bc2e-8508f29a6879.filesusr.com/ugd/d48fe3_3cc84a4443fc492a9240062eb20bf230.pdf?index=true
    • https://s3.amazonaws.com/jujadodedaruxix/black_widow_song_mr_jatt.pdf
    • https://s3.amazonaws.com/gisujubolidine/how_does_boston_market_make_their_mashed_potatoes.pdf
    • https://uploads.strikinglycdn.com/files/c845f9b6-8ef6-4b55-8e93-decca9e0553f/how_to_make_a_girl_want_you_and_think_of_you_sexually.pdf
    • https://b2f02272-107b-4032-aafc-54cdd6265a16.filesusr.com/ugd/6cf392_7305ff61b26641dd83dd6b66009229e1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/47a46c15-54b4-48fd-ba9d-6606213f5309/1684208012.pdf
    • https://s3.amazonaws.com/muxozuvalubi/nekovifevokujazedu.pdf
    • https://s3.amazonaws.com/mexijegedakol/20983045955.pdf
    • https://uploads.strikinglycdn.com/files/2ea1bc66-03f9-487f-a4b4-a634059198f0/create_your_own_small_business_website_free.pdf
    • https://98748e4b-3258-471a-903e-8ea98415cca0.filesusr.com/ugd/fd7405_e31287b4073049488ae18d74d8660258.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c7283f9c-569f-439c-bcc1-5bc8b6218f43/wordly_wise_3000_book_9_teachers_edition.pdf
    • https://4253c66a-660d-4c83-b31d-f715833d547b.filesusr.com/ugd/d9e9a0_16556d9aa73c4c84bc7e10b299a63e67.pdf?index=true
    • https://s3.amazonaws.com/gagotaniwipure/42719690955.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fa12.bin
a51b97a074caa35ee7d44f69b11aef84540a8dece0f23c2f2e9778ac76094837
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA12 5336 bytes
font_01_sfnt_off00010c56.bin
aeee9b2fd577c594ede074a7e3493832e024aab8d381a7c1d16527c2e435dd06
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C56 2252 bytes
font_02_sfnt_off00011694.bin
9cd7a78f99978134c177ff4f4d33e748f063cb9276598185cab1633aa9a20849
pdf-font-stream PDF embedded font (sfnt) at offset 0x11694 10688 bytes