Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b60ee54a02483f0…

MALICIOUS

PDF

85.7 KB Created: 2021-03-20 09:52:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: 441c32eec7b3d138392209099503d1fa SHA-1: d9382ffc9217dc1ef198707c19f5a95c2fb70fb8 SHA-256: 8b60ee54a02483f053c5e8a72f5bbc51bb2ae288fa219b3afc67f27da7076c31
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains an embedded URI pointing to 'jacksth.ru', which is likely part of a phishing campaign. The document body, though heavily obfuscated, appears to be a lure related to a carpet cleaner manual, consistent with social engineering tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=rug+doctor+deep+upright+carpet+cleaner+manual PDF link annotation
    • http://remontnatali.ru/puzagavisivugefn3qj3.pdfIn PDF document text
    • http://wspring.space/47393306084ib1.pdfIn PDF document text
    • http://shtangye.xyz/how_to_connect_bluetooth_speaker_to_alexaubla6.pdfIn PDF document text
    • http://bellissimo.online/why_is_my_kidde_smoke_alarm_going_off_for_no_reasonq0rya.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/0080bdd1-3849-4ce5-9c2e-f7d5c4de4b0c/67812887363.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1daab217-56df-4c81-a0fa-abaf0a7a8d91/how_to_use_a_diaper_genie_refill.pdfIn PDF document text
    • https://s3.amazonaws.com/gisujubolidine/what_is_an_it_business_case.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/215537ff-018b-4777-9a93-daf46e73555e/zedubedixojeludoxe.pdfIn PDF document text
    • https://s3.amazonaws.com/xeroguru/87169919005.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/67d3ca22-a7b9-49ba-95f1-ad323138206c/bible_quiz_genesis_1_with_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ecf5437e-db18-4f1b-bddb-078abea06adb/how_to_connect_symbol_barcode_scanner_to_computer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b837d000-7db0-4e3f-804a-d0067ed8963c/dark_sun_dd_5e.pdfIn PDF document text
    • https://s3.amazonaws.com/devuxuzejozam/25186138190.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f7a6cd7b-f7cb-45ac-bec7-f767b424e70e/how_much_oil_does_a_honda_gx200_engine_hold.pdfIn PDF document text
    • https://s3.amazonaws.com/timituvupame/furoxerixuserobuwedete.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4c219a7a-06dd-495d-89fc-ebbf5ccda1b9/92481005529.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bd60d8f4-3286-4dd6-abca-cf49088cef62/deroma.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010fba.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10FBA 5316 bytes
SHA-256: 13079b6b8f06a8251ccbef025a29ae9d86f950ae54c6cee12a6181c4cdd08828
font_01_sfnt_off000121ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x121AE 11760 bytes
SHA-256: c806c5a61da69dec800f2273b5af55ae2ec91350a04956229fe8f44088157e99