Malicious PDF — malware analysis report

Static analysis result for SHA-256 92c6d76df0b05baf…

MALICIOUS

PDF

131.3 KB Created: 2021-05-26 00:50:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b0eb2d30fad020de568e6a9f19de8533 SHA-1: 2dafd18cba40f932f3b0e5124a479c84fd4a20d7 SHA-256: 92c6d76df0b05baf358b9c82aded1320b55262c45b383b2fc64f8735ac189898
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URI pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also flagged this PDF as malicious. The document body is heavily obfuscated, but the presence of the external URI suggests an attempt to redirect the user to a malicious site, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=can+you+have+bubble+tea+when+pregnant
    • https://cdn-cms.f-static.net/uploads/4370076/normal_600f99b673f80.pdf
    • https://cdn-cms.f-static.net/uploads/4489052/normal_6026619b04e02.pdf
    • https://cdn-cms.f-static.net/uploads/4447108/normal_60484e7e6c9b2.pdf
    • https://cdn-cms.f-static.net/uploads/4371248/normal_5fe699b13c9b7.pdf
    • https://static.s123-cdn-static.com/uploads/4403680/normal_5fcba70693d54.pdf
    • https://static.s123-cdn-static.com/uploads/4450513/normal_5ff97fcd43308.pdf
    • https://cdn-cms.f-static.net/uploads/4367635/normal_603405f6ad97d.pdf
    • https://cdn-cms.f-static.net/uploads/4490934/normal_60660a1dd106e.pdf
    • https://cdn-cms.f-static.net/uploads/4422638/normal_5fd98368b4c13.pdf
    • https://cdn-cms.f-static.net/uploads/4474734/normal_6026069ce0736.pdf
    • https://cdn-cms.f-static.net/uploads/4486565/normal_6051ad228ef7b.pdf
    • https://cdn-cms.f-static.net/uploads/4481403/normal_5fdb6a3041945.pdf
    • https://static.s123-cdn-static.com/uploads/4418791/normal_5ffe6f4c5f76d.pdf
    • https://cdn-cms.f-static.net/uploads/4457330/normal_5fd1bcb82e62d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • https://uploads.strikinglycdn.com/files/53230013-870e-4094-bee4-daab15583cff/ti30xa_calculator_manual.pdf
    • https://s3.amazonaws.com/takebemanijewok/desiw.pdf
    • https://s3.amazonaws.com/fogibi/72573911528.pdf
    • https://uploads.strikinglycdn.com/files/b9a58813-b082-4f35-a895-19bdf105098d/brown_vs_board_of_education_significance_essay.pdf
    • https://uploads.strikinglycdn.com/files/fdfd5a32-4909-4047-aff7-5c70608bb689/you_have_won_the_victory_william_murphy_mp3_download.pdf
    • https://uploads.strikinglycdn.com/files/f7c6a044-1888-4c0a-bb86-4867cb5f0179/how_to_cure_diabetes_naturally_in_30_days.pdf
    • https://s3.amazonaws.com/pugomonapoxuxe/parse_error_apk_android.pdf
    • https://s3.amazonaws.com/baxadelefofibuz/formule_calcul_pourcentage_d_un_prix.pdf
    • https://s3.amazonaws.com/rejiner/tin_tin_restaurant.pdf
    • https://s3.amazonaws.com/daraniwekamidir/61570619677.pdf
    • https://uploads.strikinglycdn.com/files/ea2096ca-c4c0-4a75-8403-b0fdcb9f2cf7/delufafus.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b8c1.bin
1d4f627d880364e76c6f900083c99d9d05ee3df64258343cac1b63529367de8f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B8C1 5200 bytes
font_01_sfnt_off0001ca7f.bin
0b38f6fd5e0b54bfa22d5adee1cfe00629fe134100fc7cfc1ad14a2ab7974207
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CA7F 6148 bytes
font_02_sfnt_off0001da5f.bin
1f26f825d8a02662d49b4f156822375e4fb779ef941cf5fa4bf67a36e59edb9a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DA5F 10672 bytes