Malicious PDF — malware analysis report

Static analysis result for SHA-256 916fc1eaa68269d3…

MALICIOUS

PDF

73.9 KB Created: 2021-03-12 05:22:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 68a84e52725ef2a48f601bc81030f0d0 SHA-1: 1ea2853d2f61e361979388dba355c72f2649a53d SHA-256: 916fc1eaa68269d38db70e598052b69a7b60f77b28be8a33f7220486f8a6c5cd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, identified by heuristics and a machine learning classifier as malicious. ClamAV also detected it as a phishing trojan. The document body, though heavily obfuscated, contains text related to 'continental free trade area pdf 2020', suggesting a lure to trick the user into visiting the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=continental+free+trade+area+pdf+2020
    • https://cdn-cms.f-static.net/uploads/4427783/normal_6048261457494.pdf
    • https://cdn.sqhk.co/medujebukoma/34PAgh7/63241092350.pdf
    • https://cdn-cms.f-static.net/uploads/4405902/normal_60146899986e2.pdf
    • http://likedizar.medianewsonline.com/petugogosidanusurojupeziz.pdf
    • http://arbitestpark.xyz/sowinizudoxapejevakufavc6osd.pdf
    • http://xutexukoxobofi.mywebcommunity.org/historia_universal_jose_rodriguez_arvizu_3ra_edicion_gratis.pdf
    • http://5coupons.info/visual_birth_plan_template_word_documentnti46.pdf
    • https://cdn-cms.f-static.net/uploads/4416493/normal_6031d1ad80698.pdf
    • https://cdn.sqhk.co/fekoguwiwu/hjg8ib4/train_simulator_consist_builder.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://01d7ec8a-e38e-4e33-8c76-1be31754498b.filesusr.com/ugd/24d943_4bce94c9d95647eaaed38c59d2ed8f58.pdf?index=true
    • https://d75bbb92-b0e4-4b50-83e6-2443e695523b.filesusr.com/ugd/bc73b9_7be9f0dbdae24699973d19a80dc8920b.pdf?index=true
    • https://s3.amazonaws.com/zarevizebi/flowchart_template_microsoft_word.pdf
    • https://s3.amazonaws.com/zopenave/lozowojuxafa.pdf
    • https://s3.amazonaws.com/mokamoba/gerorezevikejikumijawu.pdf
    • https://01d7ec8a-e38e-4e33-8c76-1be31754498b.filesusr.com/ugd/24d943_8cc684a9628545558e0b060a9219ef6e.pdf?index=true
    • https://s3.amazonaws.com/ditiruz/rejepupa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4d0.bin
3fb124da0bec93eca571e2a68c24317056edde6ab00f1efdfd8ddd6c75f2c39e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4D0 5036 bytes
font_01_sfnt_off0000f5fe.bin
b0b9b0c21a38eb297b44faf3eb940eced68c9d6117da85a53aea2ca2e37531b1
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5FE 10624 bytes