Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d686bcbc3552800…

MALICIOUS

PDF

81.7 KB Created: 2021-03-28 12:47:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d2948e2a306cba7a858e1fda41f56ec2 SHA-1: ba16b227726b6c3cb0acc9daef24b06049ee2b87 SHA-256: 7d686bcbc3552800d1b032bc900442eac1705a84846d459bbf8881084dffbc22
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, and contains multiple embedded URLs. One of these URLs, 'https://jumiwimov.ru/award?keyword=antiplatelet+anticoagulant+pdf', is directly associated with the document's apparent theme. The PDF structure and embedded content suggest it is designed to trick users into visiting these external links, likely to download further malicious content or engage in phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=antiplatelet+anticoagulant+pdf
    • https://cdn.sqhk.co/tivuzofep/LEHgdid/finiseporafuronuxumifuka.pdf
    • http://kigowamukidiba.iblogger.org/latin_breviary.pdf
    • https://cdn.sqhk.co/bokapapukopa/cijKCgj/75878963108.pdf
    • https://cdn-cms.f-static.net/uploads/4413707/normal_6021606a5e0dd.pdf
    • https://cdn-cms.f-static.net/uploads/4495246/normal_6056026aee734.pdf
    • http://xemizawufogutuf.scienceontheweb.net/60361180286.pdf
    • http://nutepos.iblogger.org/58353854115.pdf
    • https://cdn.sqhk.co/regavebike/gihfFgd/36765896061.pdf
    • http://wide-take.top/wayne_dyer_is_he_deadcowyg.pdf
    • https://cdn.sqhk.co/niserutom/jhahgij/ticketmaster_e_tickets_to_hard_tickets.pdf
    • http://blu-ital.space/kambikuttan_noveliwiy1.pdf
    • http://komaxinatobofe.medianewsonline.com/kipefatu.pdf
    • https://cdn-cms.f-static.net/uploads/4369779/normal_5fe69d86a01d6.pdf
    • http://airet.space/fuludigumuresemubowudobe92d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://wumevagijez.epizy.com/xopewurimudamob.pdf
    • https://uploads.strikinglycdn.com/files/4b5805e0-7051-42d4-87e3-1bf80357243a/best_safety_glasses_to_wear_over_glasses.pdf
    • http://jarunitilor.rf.gd/amiodarona_efectos_secundarios.pdf
    • https://uploads.strikinglycdn.com/files/097ae71b-4d93-4bf1-b4b2-55722bd69ab9/strong_verbs_worksheet_3rd_grade.pdf
    • https://uploads.strikinglycdn.com/files/ff2940e9-cd90-486e-85c0-9c30e1b5c56a/87158650651.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001009c.bin
a3e43f4ffc30c6d188b37f1e191ceca6de79c2b064b41a18e0d051939d2c3b9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1009C 5036 bytes
font_01_sfnt_off000111da.bin
7073e1262c32eab86d3f60395bb3bfb888f364a1137ed03e51cd7e2a332cab19
pdf-font-stream PDF embedded font (sfnt) at offset 0x111DA 11300 bytes