Malicious PDF — malware analysis report

Static analysis result for SHA-256 865e774e404151a3…

MALICIOUS

PDF

73.3 KB Created: 2021-04-06 03:41:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fe88c9ec4b1bc26b87827847b0e8aed1 SHA-1: c912d86e38ae44f6ddf913c2537bb6b00d09a3fa SHA-256: 865e774e404151a3560f11db7961e9fe646c19b7151c78880ae1041eaf13650d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URI pointing to a URL designed to trick the user into downloading another PDF. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The presence of embedded URLs suggests an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=barayti+at+varyasyon+ng+wika+pdf
    • http://gurisolag.22web.org/tafedovubixukojipot.pdf
    • http://ponafutinuko.22web.org/21787128315.pdf
    • http://bajesiradevo.getenjoyment.net/sunni_bikhre_moti.pdf
    • https://tunugezujemis.weebly.com/uploads/1/3/4/3/134307821/gilikulerudaxuzixivo.pdf
    • https://tudegikugil.weebly.com/uploads/1/3/5/3/135317618/a7791fa9e.pdf
    • http://gukivuzijisuva.getenjoyment.net/97852802644.pdf
    • http://rijafinawaxus.iblogger.org/1725318020.pdf
    • http://sokavosutab.22web.org/15175975744.pdf
    • https://cdn.sqhk.co/medujebukoma/Bggtjje/interesting_facts_about_yourself.pdf
    • https://cdn.sqhk.co/sokavuwoz/fTdhc8Y/female_mannequin_head_with_hair.pdf
    • https://cdn.sqhk.co/fegukajebaj/ivjczhd/gz_motorsports_pump.pdf
    • http://dezowem.medianewsonline.com/bharat_ka_map.pdf
    • https://xadamunakufadi.weebly.com/uploads/1/3/3/9/133986396/141df3b001.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://giruwixavitunav.epizy.com/21179823497.pdf
    • http://fufuzadawefor.onlinewebshop.net/sbi_online_banking_form.pdf
    • http://gefifeji.rf.gd/68405296491.pdf
    • http://sanejiwobar.epizy.com/can_automator_convert_to_word.pdf
    • http://ledarumita.rf.gd/basic_english_grammar_part_2.pdf
    • http://milodip.epizy.com/audio_cutter_for_windows.pdf
    • http://dodekogizur.epizy.com/ford_mustang_ecoboost_engine_swap.pdf
    • https://uploads.strikinglycdn.com/files/aa0496d9-68c1-4ec1-b957-5ed1e4e2ed4e/where_is_the_power_steering_pump_located_on_a_2007_pontiac_grand_prix.pdf
    • https://uploads.strikinglycdn.com/files/e996c981-0413-469e-a77a-722ed6ee00d6/kevufisumenujiduboralew.pdf
    • https://uploads.strikinglycdn.com/files/c0f57625-ff39-4890-baf8-8934b1a9a14b/tobawosixipepugajujav.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dda3.bin
e415a4a04a8bd3a8abaa8588ce7c4a35ce2c7e7f6525d4ea5a5f36375e575e4c
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDA3 5544 bytes
font_01_sfnt_off0000f0c0.bin
879801156a33d29a12b53292fdfb56f3113c0f67af40fcd1f1a94cc7e8954b5d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0C0 11044 bytes