Malicious PDF — malware analysis report

Static analysis result for SHA-256 840ca5c9cefea102…

MALICIOUS

PDF

89.2 KB Created: 2021-04-07 05:31:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 7f5952e892a8661631f684a174f34b45 SHA-1: 9287dd3eb7a4be5425888e6b4035b5150696c44d SHA-256: 840ca5c9cefea1027cd308d9f596e9aa748a659d06a45b7db3077ea5e9d52796
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/123?utm_term=giant+defy+2+2015+size+guide PDF link annotation
    • https://fupotepalakeb.weebly.com/uploads/1/3/5/3/135351483/vovanob_neguwuba_bevezapiwi_xabewavabim.pdfIn PDF document text
    • http://souve.me/wd_my_cloud_wdbctl0020hwt-10kasop.pdfIn PDF document text
    • https://wobomiti.weebly.com/uploads/1/3/4/5/134501920/9629375.pdfIn PDF document text
    • https://cdn.sqhk.co/buwowunuras/hhiesYt/mafia_city_of_lost_heaven_soundtrack_download.pdfIn PDF document text
    • https://cdn.sqhk.co/razonavari/qjehijb/95257524549.pdfIn PDF document text
    • http://promooffer.site/jinutodegozb5la0.pdfIn PDF document text
    • https://cdn.sqhk.co/gimovitax/iMjdA75/evaluating_algebraic_expressions_quiz.pdfIn PDF document text
    • https://gebonevoduxap.weebly.com/uploads/1/3/1/6/131606392/fofupim.pdfIn PDF document text
    • http://prodson.fun/telinomokarubj2g9w.pdfIn PDF document text
    • https://cdn.sqhk.co/sidogorego/if33cDY/talking_cat_video_song.pdfIn PDF document text
    • https://cdn.sqhk.co/vasibejovej/gehhZ8y/street_fighter_iv_champion_edition_apk_download.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/3df92004-e118-4475-a50a-7c73faa11409/walmart_pack_n_play_with_changing_table.pdfIn PDF document text
    • https://s3.amazonaws.com/zafaronivaj/pumaxotogu.pdfIn PDF document text
    • https://4253c66a-660d-4c83-b31d-f715833d547b.filesusr.com/ugd/d9e9a0_8d1b5a86197344d29a936cb6d59d8a85.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/jowutoneranemuk/tiluwaresepanodugumajatu.pdfIn PDF document text
    • https://s3.amazonaws.com/jifedefujodu/38560810626.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/73e900ab-2c6e-4c2d-b6a1-818e9d14b0a4/boxagi.pdfIn PDF document text
    • https://s3.amazonaws.com/fidobakipivogit/xefekeke.pdfIn PDF document text
    • https://39472683-7d43-4bc3-882b-0947a83fd973.filesusr.com/ugd/544c7e_5b3ceea1cf3343acb170e993fe3a89ae.pdf?index=trueIn PDF document text
    • https://aa3bb5c3-2bd4-4791-9e2a-6e31d5009b04.filesusr.com/ugd/60e703_321b28151856439785537fef7e88d7b3.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fce1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFCE1 5580 bytes
SHA-256: 945f6950644435f4f0bf6d4efe0ed7b3793d30c142e9fa0482268f1f239afdd2
font_01_sfnt_off00011010.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11010 1800 bytes
SHA-256: daad3f347a4f42f432ee9983e619a7c063e36761dba5934b469418034847e28e
font_02_sfnt_off0001189e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1189E 11260 bytes
SHA-256: 754a8975ebeffc355bd6fbf60c432afda54f0ad55591e0cb505a206484a84a0b
font_03_sfnt_off00013f82.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13F82 16312 bytes
SHA-256: aad9bc0f36eadc3314e08670b59090120051e308b357201f134af3d0b781b2b0