Malicious PDF — malware analysis report

Static analysis result for SHA-256 803ecb55d6f81759…

MALICIOUS

PDF

81.4 KB Created: 2021-04-07 01:13:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a1fec308af18d57e27056fd8a9642ca SHA-1: d92734ff22d335beb0b80655c548d077696a9a10 SHA-256: 803ecb55d6f8175961f3e6bdcdc2113aa02996442fd17919850058c987277afc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain. The ML classifier and ClamAV detection strongly indicate maliciousness, classifying it as a phishing trojan. The embedded URL is likely used to deliver a secondary payload or redirect the user to a phishing site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=trumpet+music+book+pdf
    • http://tezatigobupuvu.22web.org/sol_b._com_syllabus_2017.pdf
    • https://cdn.sqhk.co/felolavap/jAEjhig/samsung_galaxy_s9_stock_ringtones_download.pdf
    • http://sujabupinoda.scienceontheweb.net/gaxefejizebaxotikovida.pdf
    • http://bezerojiw.scienceontheweb.net/bright_futures_handbook.pdf
    • http://xuvivok.22web.org/46049872078.pdf
    • http://pejofewetoz.22web.org/mulagulevib.pdf
    • https://cdn.sqhk.co/kivipemo/CsqibHb/duzibadufefubonatamarukez.pdf
    • https://cdn.sqhk.co/lupokuna/4Rghlje/48153580772.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://xajazofi.rf.gd/atv_trailer_plans.pdf
    • https://uploads.strikinglycdn.com/files/d9670dd7-452e-480d-88f6-30455daf4c10/braums_chipotle_breakfast_burrito.pdf
    • https://s3.amazonaws.com/farefasejikap/whats_your_sign_based_on_your_birthday.pdf
    • https://436010f1-0dd7-4950-aec0-3bdf337573e8.filesusr.com/ugd/5a4c69_e3ababe50ec54268a3388f8878edb339.pdf?index=true
    • https://b7d3a0ae-8059-487b-8826-088776693174.filesusr.com/ugd/8d23e4_61c7b7e7ee614b3eb7710700486582ba.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a8ed6151-4305-4559-9fba-8d2248a94293/d_and_d_measurements.pdf
    • https://s3.amazonaws.com/lovetijif/ariana_grande_all_songs_free.pdf
    • http://foxinojale.epizy.com/haier_portable_air_conditioner_12000_btu_reviews.pdf
    • https://s3.amazonaws.com/warapagefasovi/39074198359.pdf
    • https://s3.amazonaws.com/tesotiwapax/keyboard_light_not_working_hp.pdf
    • https://40785fcd-1e5e-4316-9306-5db1d5795eae.filesusr.com/ugd/2f07a1_55d610ee510c4780be533385c4ff7a32.pdf?index=true
    • https://9170d309-caca-4186-8987-bf6b40ce219c.filesusr.com/ugd/baef12_ad0bb4ceb4ec48f088a569ddb29f2a8d.pdf?index=true
    • https://s3.amazonaws.com/gifiz/grapes_of_wrath_movie_questions_answers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000efaf.bin
45e6df38992f95650f0588c43756991b56450b084882539b76c80d15b23db47c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFAF 4988 bytes
font_01_sfnt_off000100a1.bin
1466f696d9471a1e3043cdd4f61e460194ef7031bec3d58e5997c20523ea7619
pdf-font-stream PDF embedded font (sfnt) at offset 0x100A1 11704 bytes
font_02_sfnt_off000128cb.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x128CB 4324 bytes