Malicious PDF — malware analysis report

Static analysis result for SHA-256 89bd758ab2ffe731…

MALICIOUS

PDF

80.4 KB Created: 2021-04-16 05:03:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-20
MD5: 7de6b77fe09c418bb836c1cfb1c53a8f SHA-1: 9f9a7877db74c6677b0af324bb9a19e793609568 SHA-256: 89bd758ab2ffe7319d64a00e6fe9d901ea934d6911bfe8908bc4beb207787d10
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged by multiple heuristics, including a payment redirection lure and a high-confidence ML classifier, indicating a phishing attempt. The embedded URL points to a suspicious domain, likely serving as a lure for the user to update payment information. ClamAV also detected it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/strik?utm_term=interview+questions+for+hr+executive+fresher PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4365613/normal_5fe48187617cf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4467277/normal_6027c890addca.pdfIn PDF document text
    • https://cdn.sqhk.co/bukoxomule/WOghehh/android_master_sync_settings.pdfIn PDF document text
    • http://deromgroup.com/short_term_goals_for_apraxia_of_speech_in_adultsw6qv3.pdfIn PDF document text
    • http://money-team.site/74509984349n5y2o.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420939/normal_600c4616b3b6c.pdfIn PDF document text
    • https://topazezinin.weebly.com/uploads/1/3/0/9/130969714/b56a5.pdfIn PDF document text
    • https://nenovalo.weebly.com/uploads/1/3/2/7/132712003/095599b47af933f.pdfIn PDF document text
    • https://cdn.sqhk.co/tajudozizif/hijji72/incharge_debt_solutions_orlando_fl.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447903/normal_6046cd366375f.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476954/normal_5fc899d089f49.pdfIn PDF document text
    • http://copyrightsupport-ig.com/iso_27001_controlszv4qf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4405186/normal_605fd6914f2f2.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4460473/normal_5ffbc0329ea2a.pdfIn PDF document text
    • http://hookup757.fun/future_simple_worksheetmq5qa.pdfIn PDF document text
    • https://gofutetawavoror.weebly.com/uploads/1/3/0/8/130874623/3627601.pdfIn PDF document text
    • https://cdn.sqhk.co/wazikunal/aGibjfv/wipalujode.pdfIn PDF document text
    • https://cdn.sqhk.co/zisubiziwu/yheihLB/3521952513.pdfIn PDF document text
    • http://technodom11.com/how_to_turn_off_jlab_go_air_earbudsjqk0f.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/sizabo/petsafe_wireless_fence_not_working.pdfIn PDF document text
    • https://s3.amazonaws.com/xamibebulosaxug/garageband_ipad_mp3_importieren.pdfIn PDF document text
    • https://s3.amazonaws.com/nefomojuwet/android_floating_action_button_example.pdfIn PDF document text
    • https://s3.amazonaws.com/wuniku/govuwux.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fdae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDAE 5008 bytes
SHA-256: 0ef6761128d19a0f9466c673d9453dccdc34213f3d4350ca766b94c206b5454c
font_01_sfnt_off00010edc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10EDC 10916 bytes
SHA-256: 877d18788abe61b11bcd1c935e81a0483e9300c97a13bd06478087059edb6bbe