Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e5f4bbca6441f16…

MALICIOUS

PDF

84.0 KB Created: 2021-06-03 06:14:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 31ba432720b06b43b920cd8f132b92c3 SHA-1: 40bc499291204b5f0de94993f9d98dcae5adec1d SHA-256: 7e5f4bbca6441f169461cbd74977b1aec25ac4f3a81fba92df782f89ce8a5cdc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, with a high risk score. It contains an embedded URI pointing to 'https://soxebez.ru/123?utm_term=whatsapp+for+blackberry+bold+4+9900', which is likely a phishing lure related to software downloads. The document body, though heavily obfuscated, contains references that align with this lure. No scripts were extracted, but the PDF structure and embedded URI strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=whatsapp+for+blackberry+bold+4+9900
    • https://cdn-cms.f-static.net/uploads/4411270/normal_5fdc6abb81407.pdf
    • https://cdn-cms.f-static.net/uploads/4469355/normal_6030607e987ad.pdf
    • https://cdn-cms.f-static.net/uploads/4383925/normal_6012b0d14d0c5.pdf
    • https://cdn-cms.f-static.net/uploads/4490953/normal_601661233107b.pdf
    • https://cdn-cms.f-static.net/uploads/4450730/normal_605c862517e25.pdf
    • https://cdn-cms.f-static.net/uploads/4481164/normal_603b2f8e62bde.pdf
    • https://static.s123-cdn-static-d.com/uploads/4478950/normal_60b2f8261ee87.pdf
    • https://cdn-cms.f-static.net/uploads/4427514/normal_603e16ce19f93.pdf
    • https://cdn-cms.f-static.net/uploads/4480155/normal_604674a3298da.pdf
    • https://cdn-cms.f-static.net/uploads/4376609/normal_603a5e4a8a1f2.pdf
    • https://static.s123-cdn-static.com/uploads/4485818/normal_6009084d18603.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://giwupiraride.pbworks.com/f/50267540679.pdf
    • http://wuvebag.pbworks.com/w/file/fetch/144424671/is_k-12_effective_or_not.pdf
    • http://lulimogosan.pbworks.com/f/how_to_overcome_retrospective_jealousy.pdf
    • https://uploads.strikinglycdn.com/files/9681b9c1-52db-4589-8904-b6c50bb61b71/what_is_social_media_marketing.pdf
    • http://jolunatimavu.pbworks.com/f/xibudefanozu.pdf
    • https://uploads.strikinglycdn.com/files/00259d34-f1c4-40be-a78c-4d3f8bc82b68/dexupomizasa.pdf
    • http://jotoxipigi.pbworks.com/w/file/fetch/144448485/57637064589.pdf
    • http://funuvutidip.pbworks.com/w/file/fetch/144468252/alcoholics_anonymous_big_book_4th_edition_hardcover.pdf
    • http://gupiguna.pbworks.com/f/limejulig.pdf
    • http://tusoxefum.pbworks.com/f/baby_alive_grow_up_doll_black.pdf
    • https://uploads.strikinglycdn.com/files/259ced5a-cff8-47c3-bb33-49512f7bb7d5/31779175169.pdf
    • http://zajozote.pbworks.com/w/file/fetch/144456594/all_art_is_propaganda_of_some_form.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000128a6.bin
58b4a08f7bba00a2eefa5df0b59040438e008d0b4c1523645b944acbb6b4ce12
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x128A6 16908 bytes
font_00_sfnt_off0000e935.bin
7f4efd0aabccb7c9a78da2224f7f6e60459c1e0a4268ec25beef26942341fe25
pdf-font-stream PDF embedded font (sfnt) at offset 0xE935 5948 bytes
font_01_sfnt_off0000fd87.bin
3511ac049a4540696fad5d3213af568be8ac02bf60052853fcce4de1957dd1a7
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD87 13368 bytes