Malicious PDF — malware analysis report

Static analysis result for SHA-256 9491baa36da2fb1e…

MALICIOUS

PDF

114.6 KB Created: 2021-03-18 16:27:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2643eb633613e5968c9574eec241b0fe SHA-1: 71df6c3b4219e8ad95092839276cf974a66d7119 SHA-256: 9491baa36da2fb1e138900bd95452ac3f4724bcd29467f053164e8b8210e6130
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://seumenha.ru/wix?keyword=roblox+song+ids+tik+tok', which is likely a phishing lure. While no scripts were directly extracted, the PDF structure and embedded URLs suggest it is designed to redirect users to potentially harmful content, possibly for credential harvesting or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=roblox+song+ids+tik+tok
    • http://nasufulorejuwe.mywebcommunity.org/pigowejulopesunuko.pdf
    • http://neditaxuvim.getenjoyment.net/bulletproof_diet_italiano.pdf
    • http://vozivovog.scienceontheweb.net/mmoire_assurance_automobile.pdf
    • http://kurekarer.22web.org/waves_audio_plugins_free_mac.pdf
    • http://bimonetejatoleb.mygamesonline.org/23665106638.pdf
    • http://risonubokedoxav.scienceontheweb.net/jozekusufavijulipe.pdf
    • http://julapekawej.22web.org/lineare_gleichungen_aufstellen_aufgaben.pdf
    • http://xokodiraki.22web.org/biostatistical_analysis_5th_edition.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6cf80756-66c2-4d2e-b15d-ff1677cb7115.filesusr.com/ugd/2257e8_f5b9d27771a04b68af5fb03c001bc9e2.pdf?index=true
    • http://nixomirorubu.myartsonline.com/how_to_open_a_electronic_showroom.pdf
    • https://937a8a2d-b41a-4163-aff8-eda6db263557.filesusr.com/ugd/21e6f2_aa513147e8e34885b7c738c5d2e0d087.pdf?index=true
    • http://jutekoj.epizy.com/32484689217.pdf
    • https://88749095-6fd7-453f-8e8a-15b48fe47dd1.filesusr.com/ugd/e4d7df_56938ad43f0f43078e90b38ad0c4d946.pdf?index=true
    • http://fexewagesulel.epizy.com/how_to_combine_files_with_cutepdf_writer.pdf
    • http://ponuruv.rf.gd/35515361351.pdf
    • http://lujifub.epizy.com/wavuvod.pdf
    • https://04a80c79-134c-446e-801b-0c1635678e59.filesusr.com/ugd/5cebf8_6a61384dd1f74905a82a57f917915390.pdf?index=true
    • https://c208ddc4-37ec-4cef-823d-79aeaa8cd68a.filesusr.com/ugd/d34c4d_00f4876eeeb149ab81bde36bdb13d422.pdf?index=true
    • http://jowimonaperu.epizy.com/beginner_bass_guitar_book.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018595.bin
a449efadf288a63a309cb0fa24dec6b8bc029137bca29666e457a8e06754a26b
pdf-font-stream PDF embedded font (sfnt) at offset 0x18595 4964 bytes
font_01_sfnt_off00019698.bin
c6d5d1bb2115600c596518c4f72dd76c0984b1b94283984f836382f9eacf14f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x19698 11292 bytes