Malicious PDF — malware analysis report

Static analysis result for SHA-256 81d948cb79fea7b5…

MALICIOUS

PDF

89.9 KB Created: 2021-03-29 02:05:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e28d08adff93cfdd4603ab792bffbdb6 SHA-1: 2cc47ce44b09d6a3dddf9660505c59af852ae1fe SHA-256: 81d948cb79fea7b5fa89950a4f18ba7cb3e3a729f3e88f141b46de459d3537af
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by both ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains an external URI pointing to 'https://lozipotod.ru/award?keyword=mtg+objective+zoology+download+pdf', suggesting a phishing or social engineering lure. Although no scripts were explicitly extracted, the presence of embedded URLs and the overall detection suggest the file is designed to trick users into downloading further malicious content, likely through a spearphishing attachment vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=mtg+objective+zoology+download+pdf
    • https://cdn.sqhk.co/fonixoligem/Bzibjcs/zombies_2_full_movie_disney.pdf
    • http://nebo-baikala.ru/1st_grade_math_word_problems_with_picturesi25l4.pdf
    • http://idealica-italiaufficiale.site/bates_numbering_foxitfn4yy.pdf
    • https://cdn.sqhk.co/rozopebak/5ijHut2/85912245763.pdf
    • http://domainlimax.xyz/e_myth_contractor_audiobookr36mo.pdf
    • https://cdn.sqhk.co/zofizitene/7cjcLyv/titan_throne_napoleon_guide.pdf
    • https://cdn.sqhk.co/purorenutuw/jageJgf/72836829019.pdf
    • http://purpless.vip/panasonic_sd-yd250_partsfgs8v.pdf
    • http://dfwshootersupply.com/pirepobogilatinopajek6b0l.pdf
    • https://cdn.sqhk.co/zejizoguzut/gfYjehb/thumbelina_movie_frog_scene.pdf
    • http://003-center.ru/usda_nutrition_label_guidelinesx8qtn.pdf
    • https://cdn.sqhk.co/zidodovare/df7ibic/criminal_case_wiki_jones.pdf
    • http://stonersfranchise.com/big_green_egg_grill_cover_medium7rlr6.pdf
    • http://ritual-venki.online/mechanical_vibrations_raol02et.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xukonakefules/harga_avanza_veloz_2012_manual.pdf
    • https://s3.amazonaws.com/lakujusitejojet/cajun_fiddle_sheet_music.pdf
    • https://s3.amazonaws.com/vetamedisoz/64734679132.pdf
    • https://s3.amazonaws.com/bubisifapagefe/aluta_gyration_song.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010a1e.bin
d7f1b6c24332a7169c66ad254afebf049fd252815c704f5d6aa7f61c5b2756a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A1E 5572 bytes
font_01_sfnt_off00011d69.bin
c97084fb9bbed2cb5ad7241807d7bee888975530e9aa73cc305a3e3726931594
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D69 11348 bytes
font_02_sfnt_off00014461.bin
f5ebc6c20ddb12b7a35d9e93c4417f067bd11a8f8c8f6b709580d841b3272307
pdf-font-stream PDF embedded font (sfnt) at offset 0x14461 16336 bytes