Malicious PDF — malware analysis report

Static analysis result for SHA-256 85e2342a92f800f9…

MALICIOUS

PDF

74.8 KB Created: 2021-03-05 05:40:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 0190ebffa96b1e895f86bde8e3004f73 SHA-1: 34e1d05de0a8922736b99fe3ab5ec1c06056cb4f SHA-256: 85e2342a92f800f9fe8a8d7fa9bccf221df0665cf2f60c462792cc9f89721c4a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI that directs users to a URL associated with a search query for a product manual. This URL, along with other extracted URLs, suggests a phishing or scam attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wb?keyword=casio%20w%20201%20manual PDF link annotation
    • http://lumobumekola.getenjoyment.net/80834998194.pdfIn PDF document text
    • http://gakagebir.mypressonline.com/is_war_room_based_on_a_book.pdfIn PDF document text
    • https://cdn.sqhk.co/morureju/ijcLgcl/word_finder_scrabble_with_friends.pdfIn PDF document text
    • https://cdn.sqhk.co/gederanew/hjYC3gd/68704112888.pdfIn PDF document text
    • https://cdn.sqhk.co/kizafizutuw/NghasU4/jobovamusokugu.pdfIn PDF document text
    • https://cdn.sqhk.co/tevunufoba/2haNB7f/76473453333.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/lopadivupudexa/link_video_er_app.pdfIn PDF document text
    • https://s3.amazonaws.com/nademopor/kala_bazar_old_movie_song.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/748c1b4d-0c13-4d64-a1b0-59b8d49fec81/colombians_in_america.pdfIn PDF document text
    • https://s3.amazonaws.com/buganabowumujef/matching_adjectives_to_nouns_worksheets.pdfIn PDF document text
    • https://s3.amazonaws.com/xujitezu/converter_mp4_to_avi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0af72fd9-8081-4623-94aa-c0527f28962f/xadadenotukufowaturoxo.pdfIn PDF document text
    • https://s3.amazonaws.com/janodojivi/46462951429.pdfIn PDF document text
    • http://gafodix.myartsonline.com/how_to_give_a_compelling_interview_presentation.pdfIn PDF document text
    • https://s3.amazonaws.com/datarofapakil/aarhus_city_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/vetamedisoz/chlorella_nutritional_information.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c97f5269-1fc6-4c14-a172-3820188c180c/32236589975.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/571595f3-6c61-4bd1-933e-57f9d1276f68/why_is_my_ice_maker_making_a_clicking_noise.pdfIn PDF document text
    • https://s3.amazonaws.com/xafaxotaful/unguided_heartbleed_bug_lyrics.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e1882bdc-0fb8-4feb-930c-6d3a663e93cc/how_do_i_reset_my_midea_washing_machine.pdfIn PDF document text
    • https://s3.amazonaws.com/lakadutof/hello_movie_anaganaga_song_ringtone.pdfIn PDF document text
    • https://s3.amazonaws.com/sizabo/plano_de_aula_educao_infantil_formas_geometricas.pdfIn PDF document text
    • https://s3.amazonaws.com/bisegilupuf/xopowanabivenozaveja.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d6d1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD6D1 4860 bytes
SHA-256: 4d48c13a5cc7d9dc62d0f4a88bde65f08ef03073bf4285c2fda204198be3158c
font_01_sfnt_off0000e744.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE744 11888 bytes
SHA-256: 07d844a17f63cae781d6cea6b6c597265bc5e151065b24b286c683b9daff54f7
font_02_sfnt_off00010e7d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10E7D 4324 bytes
SHA-256: d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378