Malicious PDF — malware analysis report

Static analysis result for SHA-256 953eb0dbb513e9df…

MALICIOUS

PDF

76.6 KB Created: 2021-02-28 04:29:39 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 6c9fafff8a54743a865debda26ca70dd SHA-1: 8fd608cd23c172ff74a091de4667f318b3922f33 SHA-256: 953eb0dbb513e9df8a2992aa8b240b4b2252f38c1e829c8cd5cf3502ec1f7acc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain. ClamAV and ML classifiers have identified this file as malicious, specifically a phishing trojan. The document body, though heavily obfuscated, appears to be a lure related to appliance troubleshooting, intended to drive users to the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=troubleshooting+a+kitchenaid+refrigerator+ice+maker PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4368976/normal_5fddd00f8030f.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4451549/normal_6005a1bc6a52d.pdfIn PDF document text
    • https://cdn.sqhk.co/papowepu/ohgPsih/80144050833.pdfIn PDF document text
    • http://vuvulusigi.scienceontheweb.net/zipupozipuxinatiwinisada.pdfIn PDF document text
    • https://cdn.sqhk.co/tigixexaxi/h5jbicz/sago_mini_airport_app.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4389355/normal_6015294c592f1.pdfIn PDF document text
    • https://cdn.sqhk.co/pawanipol/HO3jdhj/84682974698.pdfIn PDF document text
    • http://lujotagefizoga.iblogger.org/kilojezag.pdfIn PDF document text
    • http://befotuke.mywebcommunity.org/23276884275.pdfIn PDF document text
    • https://cdn.sqhk.co/mepapogivoma/ihvs3Mb/best_random_video_chat_apps_for_android.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/xidulumexi/composition_of_functions_student_activity_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/kimone/how_much_does_epic_cost_for_private_practice.pdfIn PDF document text
    • https://s3.amazonaws.com/divexikav/live_wallpaper_de_anime_para_android.pdfIn PDF document text
    • http://palalujopaxuv.epizy.com/cursos_gratuitos_primeros_auxilios_cruz_roja.pdfIn PDF document text
    • http://rogunug.epizy.com/88337590928.pdfIn PDF document text
    • https://s3.amazonaws.com/vavejijitatofu/54212167790.pdfIn PDF document text
    • https://s3.amazonaws.com/xamibebulosaxug/below_her_mouth_movie_mp4.pdfIn PDF document text
    • http://zijodere.rf.gd/cartoon_video_cartoon.pdfIn PDF document text
    • http://jabodegodonirad.atwebpages.com/how_to_remove_rosetta_stone_from_mac.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef74.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF74 5588 bytes
SHA-256: 0102f1cdb072c7686fbcfebd23c1892a71d1d488794bd3f03e471c212341309e
font_01_sfnt_off0001024b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1024B 10040 bytes
SHA-256: 726ea559ecb675e3e5f4b4f12e25adaeb6fa27072de412d4f34e2367832040b2