Malicious PDF — malware analysis report

Static analysis result for SHA-256 9715315a557d2002…

MALICIOUS

PDF

83.1 KB Created: 2021-04-05 01:18:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 171bd9f495e4968cd5a4a8aacf47fc19 SHA-1: b1f4078190dc31d729c37f4be50a14a7503b770c SHA-256: 9715315a557d20026574c92191faba02cdf96c7fb8398010d2da54d3385c5d34
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, and the document body text suggests a lure related to 'reloading kits for sale'. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=reloading+kits+for+beginners+for+sale
    • https://cdn-cms.f-static.net/uploads/4402519/normal_5fd7c01d5158a.pdf
    • http://zomolejefej.mywebcommunity.org/piwumakiwikofimob.pdf
    • https://cdn-cms.f-static.net/uploads/4366309/normal_605d7645a6b8b.pdf
    • https://cdn-cms.f-static.net/uploads/4366319/normal_60153cbd203a3.pdf
    • https://cdn-cms.f-static.net/uploads/4450730/normal_604f35d520247.pdf
    • http://xalenupom.getenjoyment.net/64562271207.pdf
    • https://cdn-cms.f-static.net/uploads/4462374/normal_5fe6967ab84d4.pdf
    • https://static.s123-cdn-static.com/uploads/4444866/normal_6004868707fe6.pdf
    • https://cdn-cms.f-static.net/uploads/4470696/normal_603ea0c84d465.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • https://s3.amazonaws.com/fosalizuzu/autumn_coloring_sheets_for_preschool.pdf
    • https://s3.amazonaws.com/vukumesoj/14825995298.pdf
    • https://s3.amazonaws.com/palevijuj/facebook_video_format_not_supported.pdf
    • https://s3.amazonaws.com/legipalofi/jimedalejerukegaz.pdf
    • https://s3.amazonaws.com/legapatatezisa/brother_hl-l2380dw_wont_connect_to_wifi.pdf
    • http://ramufezumax.rf.gd/17697508957.pdf
    • http://lapizepo.rf.gd/primed_to_perform.pdf
    • http://vodukipezep.rf.gd/wefavobemazeji.pdf
    • https://s3.amazonaws.com/tomamujuf/what_receivers_work_with_spektrum.pdf
    • https://s3.amazonaws.com/gurupixabogivaz/frantz_fanon_and_emancipatory_social_theory.pdf
    • http://vedumojaje.epizy.com/ditolapijijunixagobeloje.pdf
    • https://s3.amazonaws.com/jenisozazewubo/inventory_aging_report_in_sap_bw.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f6f8.bin
b42d799514de42a1c2ef13d03a07ec45a35f3600617a972a51a92704250042f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6F8 5284 bytes
font_01_sfnt_off000108fc.bin
58b4873d33ac9fffaf45ed1a2312b8eb5fadf3b067e77f8cfe9e87095f6a7717
pdf-font-stream PDF embedded font (sfnt) at offset 0x108FC 6068 bytes
font_02_sfnt_off000118ad.bin
e0f1bb3646ca0da6ffaaebcb5d7d119319fd642fde8ece4ff62c28c7c258ee81
pdf-font-stream PDF embedded font (sfnt) at offset 0x118AD 11060 bytes