Malicious PDF — malware analysis report

Static analysis result for SHA-256 91b9592e579707ec…

MALICIOUS

PDF

77.2 KB Created: 2021-03-18 22:03:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: df96b8c572a85d92c5ceb4720aaf2f4a SHA-1: 7415571a28ec4d1adab5e25c74459150ab3862e9 SHA-256: 91b9592e579707ec429a358a69c13ee757d00a307f7bec81f87e81f5ca59492a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that mimics a search result for a specific manual, likely to trick the user into clicking it. This URL leads to a malicious domain identified by heuristics and ClamAV as a phishing or trojan delivery mechanism. The ML classifier also strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=radio+shack+weather+radio+manual+20-315
    • http://xovuwowim.mypressonline.com/como_hacer_un_con_imgenes_en_celular_iphone.pdf
    • http://kogutojoveso.mywebcommunity.org/what_is_the_setting_at_the_beginning_of_araby.pdf
    • http://rigudozefogo.mypressonline.com/sewing_book_free.pdf
    • http://mosemajubuj.22web.org/pokerusodapo.pdf
    • http://mobile-media.moscow/spanning_tree_protocol_stepsm6t5h.pdf
    • http://kinoxca.xyz/nevegadotuxikazepuvkrb37.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/votubukaxogilix/atos_2018_financial_report.pdf
    • https://s3.amazonaws.com/getizar/sezoj.pdf
    • https://s3.amazonaws.com/taturi/kifanologakab.pdf
    • http://jigisasamupor.onlinewebshop.net/44095884638.pdf
    • http://jidabalelibixu.rf.gd/8th_book_back_questions_and_answers.pdf
    • https://s3.amazonaws.com/lodazojamuva/16590576221.pdf
    • https://s3.amazonaws.com/mogedozara/bomixipogu.pdf
    • http://luxupuxud.myartsonline.com/77693271425.pdf
    • https://s3.amazonaws.com/foneniz/48279660048.pdf
    • https://s3.amazonaws.com/fixararololu/89500902121.pdf
    • https://s3.amazonaws.com/timeziso/where_to_buy_cateye_bike_computer.pdf
    • https://s3.amazonaws.com/minabiwa/ecg_worship_songs_2018.pdf
    • https://s3.amazonaws.com/vipuxafol/free_business_powerpoint_templates_2018.pdf
    • https://s3.amazonaws.com/vokeri/12457886969.pdf
    • https://s3.amazonaws.com/jajuzasalikirut/is_there_a_metro_system_in_los_angeles.pdf
    • https://s3.amazonaws.com/najipavez/43650126339.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dee5.bin
f3bdbe93ef5a06885fb827824986746c17291db2205f7a2c4884c16e7a98d306
pdf-font-stream PDF embedded font (sfnt) at offset 0xDEE5 5868 bytes
font_01_sfnt_off0000f2d1.bin
e8922053e8ceeb7114aadc772b9919e3442a605041fc824ebb4d8e7a7cd49bcf
pdf-font-stream PDF embedded font (sfnt) at offset 0xF2D1 11356 bytes
font_02_sfnt_off00011927.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x11927 4324 bytes