Malicious PDF — malware analysis report

Static analysis result for SHA-256 956af680b4c42ffe…

MALICIOUS

PDF

76.5 KB Created: 2021-03-18 15:58:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4d491ee0fb27f7b9a30c2995ecd10b03 SHA-1: 9bfe191f00891dc79ab8b046292f4b3b6c30bcba SHA-256: 956af680b4c42ffe5c05e863189b31fd94239f62dce3aad0343ce9a231380e66
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is identified as malicious by multiple heuristics, including a high-confidence ML classifier and ClamAV detection. The 'SE_ADVANCE_FEE_SCAM_LURE' heuristic indicates the document's content is designed to trick users into a fraudulent scheme involving prizes or funds. The embedded URL points to a suspicious domain, likely part of the scam infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=florence+nightingale+movie+1985
    • https://cdn.sqhk.co/jimavidozeze/rje32ic/84518822363.pdf
    • https://cdn.sqhk.co/jawutuwek/Uuhjfih/mountain_car_drive_download.pdf
    • http://shop-onlain.fun/drivers_para_mini_laptop_acer_aspire_one_d257_windows_7yqwlk.pdf
    • http://my-favshope.online/clulas_falciformes_tratamiento_naturali0yxq.pdf
    • http://pifumufupes.iblogger.org/transformers_combiner_autobots.pdf
    • https://cdn.sqhk.co/jidulopavoji/Aniegim/polaroid_originals_onestep_picture_size.pdf
    • http://kepukarob.sportsontheweb.net/pokemon_sun_and_moon_cosmic_eclipse_card_prices.pdf
    • http://bloomwithdeanna.com/gabuzagisalaxiwedkrfdw.pdf
    • https://kazanuwe.weebly.com/uploads/1/3/2/6/132683097/7954527.pdf
    • https://cdn.sqhk.co/pajelidul/b2ivXYc/bixugafomazepuzaroxasa.pdf
    • https://vaxudiku.weebly.com/uploads/1/3/4/7/134709892/wineluxa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://944456f3-75eb-4cd6-bbfd-656b3713ada1.filesusr.com/ugd/2c8d66_335e993065ec429a96a3eccc420d54dc.pdf?index=true
    • http://pavemamixazose.rf.gd/transgenic_plants_bt_cotton.pdf
    • http://zitadufafasid.onlinewebshop.net/33873577675.pdf
    • http://kivozusemu.atwebpages.com/mr_heater_big_maxx_installation_video.pdf
    • http://sedukoxiwu.epizy.com/dixexomowugelifutigebon.pdf
    • https://efed9c07-4553-4484-a419-1b844d271aeb.filesusr.com/ugd/6f475a_274308312ece4f4f88a5881ef51c5d37.pdf?index=true
    • https://f3b8d348-8566-49c9-a9f8-a2c3b9e1bc8e.filesusr.com/ugd/f1c748_dfc4e0cfa95c495db0480c10a5e4f4c2.pdf?index=true
    • https://e301b21f-f707-426c-a094-6199d4b1a2d6.filesusr.com/ugd/f65518_cb1ef91c793b4c1e88c61fa6b9d26237.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec90.bin
da0f908ce37b8f13b10a8762fe2a0fb259590c60024671554fa06e8af8f5e457
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC90 5576 bytes
font_01_sfnt_off0000ff70.bin
4a8f64ecce9f826ab777de6c3fdbb1ccaf5aca42ae88e7a3934a59580b9fb873
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF70 11120 bytes