Malicious PDF — malware analysis report

Static analysis result for SHA-256 85910ff132d909bd…

MALICIOUS

PDF

79.1 KB Created: 2021-04-03 12:39:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3006735add7df9a2452ea00c37856fa3 SHA-1: 7cd2393157b728f625c19a2159fac0e31dc55bea SHA-256: 85910ff132d909bd30a64ac54b7e730f902babea718e1b4cef56796bd943c013
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic indicating an external URI, specifically 'https://dafemum.ru/wix?keyword=causality+5+unblocked'. The document body, though heavily obfuscated, contains text related to 'Causality 5 unblocked', suggesting a lure to trick users into visiting the malicious URL. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=causality+5+unblocked
    • http://startask.ru/rubber_foam_sheet_for_sofa69vys.pdf
    • http://granitmetrospecstroy.ru/55456512635xgb75.pdf
    • http://sayseedokg.com/rofuvikowizowofi91f6x.pdf
    • http://jatukamopefu.22web.org/price_elasticity_of_demand_formula.pdf
    • https://cdn-cms.f-static.net/uploads/4466154/normal_6065de0851cbe.pdf
    • https://cdn-cms.f-static.net/uploads/4388038/normal_604fd58dece58.pdf
    • https://cdn-cms.f-static.net/uploads/4473938/normal_606521d1c2cd9.pdf
    • http://fbcopyright-center.com/vegetarian_diet_for_weight_loss_meal_planeq4sr.pdf
    • http://nuxokavarop.22web.org/what_does_science_tell_us_about_gender.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://puzexexaniledow.epizy.com/penejiwefuz.pdf
    • http://getagikodatikul.epizy.com/nelson_math_textbook_grade_6_questions.pdf
    • http://wojobawezelo.rf.gd/33299281455.pdf
    • http://tagutibebik.rf.gd/anna_karenina_full_book.pdf
    • http://timojakizufijad.rf.gd/gunpla_warfare_event_guide.pdf
    • https://s3.amazonaws.com/xesigeze/8465174758.pdf
    • https://s3.amazonaws.com/faduxodiwo/54860581761.pdf
    • https://s3.amazonaws.com/satuja/guide_to_completing_china_visa_application.pdf
    • https://979cd01f-16ea-4d2c-b189-234964c95597.filesusr.com/ugd/d4c4cf_6a8d0d88ed2d4d39b0455c1cb159255d.pdf?index=true
    • https://s3.amazonaws.com/vipinib/best_inshore_fishing_guide_in_orange_beach.pdf
    • https://492f55f4-3442-4b37-b17e-39d9f2f0ae8a.filesusr.com/ugd/7dfe85_19b7c89d61af46bcbecd5246ebcbe0ba.pdf?index=true
    • https://s3.amazonaws.com/bivanud/79965946796.pdf
    • https://5efcf519-4c71-4be9-a00f-e1d47ba804c5.filesusr.com/ugd/ebcc4b_eeb0f6d8fd994223a82a52e265cf7328.pdf?index=true
    • http://kulolepan.rf.gd/lobby_hero_kenneth_lonergan.pdf
    • https://0d555108-1732-4721-8d72-76d747b2053a.filesusr.com/ugd/1b0481_d506898098464b7f87f42e97ab185db1.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebcf.bin
a6f5d4ead3d38a02483b599bda536086f6202c43584d35d4c5987509458259bf
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBCF 5172 bytes
font_01_sfnt_off0000fd81.bin
5712ec38345e429755d70cfcda33830133057d6df6443005a4d008038629663f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD81 10336 bytes
font_02_sfnt_off000120e4.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x120E4 4324 bytes