Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fc3e527e5258dc7…

MALICIOUS

PDF

82.2 KB Created: 2021-03-20 14:46:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fcce66d1bd25ee17250889be10d6935 SHA-1: e4c3d437f2f2f319154591ee031c5a670327047b SHA-256: 7fc3e527e5258dc7b68e89a8dfb19c2908e1be009d6eee43f96ac28c01a9670d
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by ClamAV as a phishing trojan and ML classifiers. It contains an external URI pointing to 'zajinet.ru', which is likely part of a phishing campaign. The document body, though heavily obfuscated, contains text related to 'Navy training center in gujarat', suggesting a targeted lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/aws?utm_term=navy+training+center+in+gujarat
    • https://cdn.sqhk.co/tevunufoba/jb9mhao/fevunawoxubadukixovup.pdf
    • http://tuderoba.getenjoyment.net/sobetabaj.pdf
    • https://cdn.sqhk.co/xakatikakizi/TRtWfji/hurricane_outbreak_apk_mod.pdf
    • http://gexulogoben.sportsontheweb.net/developmental_psychology_articles.pdf
    • https://cdn.sqhk.co/nububufi/j9Zaihc/fifa_world_rankings_2014.pdf
    • http://wabuxon.iblogger.org/the_dallas_buyers_club_parents_guide.pdf
    • http://revenularozudo.66ghz.com/vipaxuleretuza.pdf
    • http://pejokepi.mywebcommunity.org/pogorezabaluxepuv.pdf
    • https://cdn.sqhk.co/xovopebe/ksDDOhb/84042950795.pdf
    • https://cdn.sqhk.co/wodelaganav/kpGjcPo/vemupakogakoxafatuxilupa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://molijogur.epizy.com/sololedopezupogurini.pdf
    • https://uploads.strikinglycdn.com/files/67972563-6b8b-4b32-ad7c-24c044758d16/hp_laserjet_pro_400_toner_replacement.pdf
    • https://s3.amazonaws.com/metubevozisul/acta_constitutiva_de_sociedad_anonima_en.pdf
    • https://s3.amazonaws.com/baxadelefofibuz/junusomevegi.pdf
    • https://s3.amazonaws.com/fomudebipefasu/naledipotazixepuvumis.pdf
    • https://s3.amazonaws.com/towutoginadivu/jiluk.pdf
    • http://tipokeviti.atwebpages.com/chemistry_experiments_for_life_science_majors.pdf
    • https://uploads.strikinglycdn.com/files/407f9aba-7be7-4abf-a908-57e5467ba13e/bowling_string_pinsetter_price.pdf
    • https://s3.amazonaws.com/xuxifuzituwu/escribir_email_formal_en_ingles.pdf
    • https://uploads.strikinglycdn.com/files/d4173ea9-70bd-4c24-8521-c31e1a2b70df/gigulovasoj.pdf
    • https://uploads.strikinglycdn.com/files/e94b9a68-7601-423a-8e4e-77a466a8c88b/words_to_describe_the_rainy_season.pdf
    • https://uploads.strikinglycdn.com/files/75799ec1-f33f-4a25-9620-1f52ef7c72ce/59568998947.pdf
    • https://s3.amazonaws.com/fejififimaketo/anatomia_de_amigdalas_y_adenoides.pdf
    • https://s3.amazonaws.com/tofizo/bihar_board_registration_form_2020.pdf
    • https://s3.amazonaws.com/zewimu/azure_devops_pipeline_yaml_template.pdf
    • https://s3.amazonaws.com/filidabut/how_to_increase_calories_in_infant_formula.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103d0.bin
ae041934f8732696aeb70c4e9864124fcc8e9b5a183fcf680484cab7afb75245
pdf-font-stream PDF embedded font (sfnt) at offset 0x103D0 4964 bytes
font_01_sfnt_off000114e1.bin
cd305eab27661461f5df19de803ac20315af22d27f2ecf6adea15bf6a428e61e
pdf-font-stream PDF embedded font (sfnt) at offset 0x114E1 11036 bytes