Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a5c2d20535994d3…

MALICIOUS

PDF

93.3 KB Created: 2021-03-19 10:02:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 25915a99ea4449d4e7fafb5c7897acc7 SHA-1: 5091c22e25fc08f2f489a4ace11b99abf0ee3845 SHA-256: 7a5c2d20535994d3503422ebf7374102ea4a7b452d7bd539b2d47e9050077c5d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that masquerades as a search result for a popular video game, likely to trick users into clicking it. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to a malicious site, potentially for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=load+order+skyrim+xbox+one+2020
    • http://pikegupima.medianewsonline.com/36897461893.pdf
    • http://nitanupemil.mygamesonline.org/api_510_inspector_salary_in_canada.pdf
    • http://kopatizukuxaluj.scienceontheweb.net/bswa_308.pdf
    • http://supariwepexafat.mywebcommunity.org/30609064127.pdf
    • https://cdn.sqhk.co/rudolikube/gcjbgfq/bubble_shooter_blast_legend_mod_apk_unlimited_money.pdf
    • https://cdn.sqhk.co/xazewizol/ajiZoge/zavobejumelivesu.pdf
    • https://cdn.sqhk.co/vegubefeno/ieojiW6/52106654370.pdf
    • http://gekodejevotug.medianewsonline.com/shell_scripting_tutorial_point.pdf
    • http://wewofif.scienceontheweb.net/bacteria_bordetella_pertussis.pdf
    • https://cdn.sqhk.co/gisepavuv/UvjihgT/kodiak_tents_black_friday.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://4e4301d6-cc9a-4939-960a-6b497c1efea6.filesusr.com/ugd/d78803_e812170a229e4fff972706612b5879ef.pdf?index=true
    • https://57fc24c6-ba7c-430a-bdae-05304608b610.filesusr.com/ugd/bc9c68_76f217e9038044219d045e28d7f5fb81.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c2045fec-75d2-4f97-ad2e-2dd15bec6665/how_to_interpret_data_science.pdf
    • https://8533cbf3-c0d6-400c-bdf8-8ca38cf0242b.filesusr.com/ugd/135178_ef75f57804554fd2852f47810dfb48fa.pdf?index=true
    • http://megugasawixige.onlinewebshop.net/speak_now_1_workbook_download.pdf
    • https://uploads.strikinglycdn.com/files/0e3f180f-5fe9-46dc-a984-2be3c382b76a/minn_kota_riptide_ulterra_80_parts.pdf
    • http://zeroxezubanalil.onlinewebshop.net/c_web_development_tutorial.pdf
    • http://pedirite.onlinewebshop.net/principles_of_mathematical_analysis_download.pdf
    • https://574dee49-ee40-4737-ae02-340ce2b26f9d.filesusr.com/ugd/b44cf7_ad980f92a31543b983ba49241e52be4d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/8bb58904-fa4c-4fad-9991-2a7b240667a4/21144915035.pdf
    • https://054d5c26-596f-48a3-87a7-0fc79031e5db.filesusr.com/ugd/599026_0ac1166e66bf4b229efe08ae62d5b7e2.pdf?index=true
    • https://da89e6ec-52f9-4c28-8de8-447a2e923c0c.filesusr.com/ugd/5e5b2a_8778a82f725f48999c79b8e1701f0861.pdf?index=true
    • https://f1801c53-b3f5-4b94-a9b3-4bb8eb376a66.filesusr.com/ugd/af633f_4227dffd5f324309a4d34a5e6af30b1e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012d2f.bin
7f7dd91c187861c1196346b2325c93c510adbfc5c34e948a8a61acbda14da1db
pdf-font-stream PDF embedded font (sfnt) at offset 0x12D2F 5528 bytes
font_01_sfnt_off00013ff4.bin
607b09ca7806cbde6f6c8ae101b97482ea7ebd98eb7805bb186ac951d293d4cf
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FF4 11792 bytes