Malicious PDF — malware analysis report

Static analysis result for SHA-256 91fb00aef646effb…

MALICIOUS

PDF

74.3 KB Created: 2021-03-30 23:29:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e90cd3b16b2c34c8721880a80b153c9a SHA-1: 7487d86e56c919c8896c6dd9bed7be27384ee14c SHA-256: 91fb00aef646effbf17f4e98b94b60621196d1c413b3bf89ce82adf8d17fecd4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, which is indicative of a phishing attempt. ML and ClamAV heuristics strongly classify this file as malicious, specifically as a phishing trojan. The document body, though heavily obfuscated, contains keywords related to awards and file names, suggesting a lure to trick users into visiting the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/award?keyword=the+art+of+taking+action+hung+pham+pdf
    • http://artistichomesolutions.com/xekagotuwidamedawiwi4v6kj.pdf
    • http://todayshop.website/what_are_some_idolatrous_symbols_popular_in_our_culture8nwli.pdf
    • http://lazadacostumercenter.com/379567880584v748.pdf
    • http://uscovidcharts.com/calligraphy_tutorial_freesxhss.pdf
    • https://cdn-cms.f-static.net/uploads/4365591/normal_604345efed7aa.pdf
    • http://tixshopclub.fun/77420983308yg6ca.pdf
    • https://cdn-cms.f-static.net/uploads/4380211/normal_6051e491efa4a.pdf
    • http://oyuncuxx.com/vadejepobovogifenelphyo.pdf
    • https://static.s123-cdn-static.com/uploads/4446152/normal_5fe3dbdbb8d4e.pdf
    • http://tokio-2020.fun/wosomop93f81.pdf
    • https://static.s123-cdn-static.com/uploads/4410965/normal_5fe38140c1a36.pdf
    • https://cdn-cms.f-static.net/uploads/4409621/normal_5fdc2784ba5a8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2eca5409-ff03-4aed-9a4f-62676570b3fc/8221842111.pdf
    • https://uploads.strikinglycdn.com/files/bc2ad963-1c2b-4abc-815a-58296cac8578/husqvarna_455_rancher_carburetor_adjustment_tool.pdf
    • https://uploads.strikinglycdn.com/files/a75f16c1-1d4e-468d-8ba4-9b3bf5003955/zunevomoze.pdf
    • https://uploads.strikinglycdn.com/files/e6523fdd-2647-4891-a147-1d859aad357a/rotekaxesafomurelowi.pdf
    • https://uploads.strikinglycdn.com/files/ff9523d9-4e7a-4011-9999-e8d5df2677ac/1996_ford_ranger_xlt_extended_cab_bed_length.pdf
    • https://uploads.strikinglycdn.com/files/4988ab10-f2dd-4b04-a412-bb19b0ccfba1/kindle_3_keyboard_firmware_update.pdf
    • https://uploads.strikinglycdn.com/files/66f508c3-5427-4cb8-a432-2e66c2262253/nofodukovewewozose.pdf
    • https://s3.amazonaws.com/julaxel/sigalejun.pdf
    • https://s3.amazonaws.com/gewisetug/mutual_information_categorical.pdf
    • https://uploads.strikinglycdn.com/files/f42b3011-2975-494e-ae28-5375e4130a55/gaduwenilewabedemabenevo.pdf
    • https://uploads.strikinglycdn.com/files/caf6851e-673a-4637-b0ac-fe2259b66cda/onetouch_ultra_2_control_solution.pdf
    • https://uploads.strikinglycdn.com/files/9d1faa56-79ff-45f3-a1f1-429cc859efbb/systems_engineering_masters_program.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e2ba.bin
af53e51f242e84f466f6c54419a3d6eae200de7eb7a84ddb5806366eb5496293
pdf-font-stream PDF embedded font (sfnt) at offset 0xE2BA 5372 bytes
font_01_sfnt_off0000f4d6.bin
c6f8eb89daa9a480d0e0b50a010e99ffe4b19bff1c664cd780c0a6ba77d03af6
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4D6 11340 bytes