Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a73b393ebe8b8d0…

MALICIOUS

PDF

327.4 KB Created: 2021-03-01 22:04:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 9088a02b01987aadd80a97f7b101c219 SHA-1: b2f30f10fe21916fabf36ebe69ad1380e9c5de49 SHA-256: 9a73b393ebe8b8d0636df7bca194afbaff0ded96650281cd9ea93d28bfd3a1b3
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The document body, though heavily obfuscated, suggests a lure related to 'text sad face symbols', likely intended to trick users into visiting the malicious URL. No scripts were extracted, but the presence of external URIs and the ClamAV detection strongly indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.2189

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=text+sad+face+symbols PDF link annotation
    • http://lesanuzununefa.22web.org/97877782578.pdfIn PDF document text
    • http://dektesheff.xyz/jspdf_html2canvas_blurryhpgyl.pdfIn PDF document text
    • http://goods-amzon.com/gatujatf3ef.pdfIn PDF document text
    • https://cdn.sqhk.co/tegimatararo/Bejh938/auto_picture_background_remover.pdfIn PDF document text
    • http://juzibekemuvur.iblogger.org/bhaiya_song_tamil.pdfIn PDF document text
    • http://detonic-italy.website/bitikodariyt1x6.pdfIn PDF document text
    • http://womenit.space/biological_diversity_definitionb9qgf.pdfIn PDF document text
    • http://towumodoxilokox.22web.org/temif.pdfIn PDF document text
    • http://farvestnn.ru/nigabotedimevekamogtwoga.pdfIn PDF document text
    • http://newsportstechnology.ru/amino_acids_biochemistrymztbi.pdfIn PDF document text
    • http://lightly.store/maluvorzmtvk.pdfIn PDF document text
    • http://blacklaser.ru/par_quoi_remplacer_la_creme_liquide_dans_une_saucezaxob.pdfIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://livofos.epizy.com/graduation_gift_certificate_template_word.pdfIn PDF document text
    • http://zevijefe.rf.gd/22971532280.pdfIn PDF document text
    • https://s3.amazonaws.com/kalanejaxutilif/how_long_do_stock_trades_take_to_settle.pdfIn PDF document text
    • https://s3.amazonaws.com/rodiligarexo/calendario_serie_a_2020.pdfIn PDF document text
    • http://josejutolaxof.rf.gd/35411138839.pdfIn PDF document text
    • https://s3.amazonaws.com/vidadaviwal/65420096708.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlTibetanIn PDF document text
    • https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 16

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off0002150f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2150F 1788 bytes
SHA-256: cf2f42e0f0ea6ab6b0be22979fb4c20c642b63436fed8dc8ae3b2f1f693e9c9b
stream_011_off0002272f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2272F 151152 bytes
SHA-256: 29fe98c5361ec6c7c6af8845c8eadc4b4d0023d3782c8a6c7ba54b4bd1680af1
font_00_sfnt_off000181a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x181A8 7052 bytes
SHA-256: 3702df6840b7c9b3e76a5e543a271af16136cfab214473e9e65db2f995ff94fb
font_01_sfnt_off000193d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x193D4 17688 bytes
SHA-256: b8dcec1e17998167661a4bf457bdc2e213dd1c7c03e3bec4122ddc191cbe5d84
font_02_sfnt_off0001cc4c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1CC4C 5332 bytes
SHA-256: 6aef6b3d3189dc01fb9d70cc7df760e710393e8d889f92640ff61ccb1f931308
font_03_sfnt_off0001de2f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1DE2F 7544 bytes
SHA-256: b2469fd68a615a5d129c075e1d4b083eafdf172077617b6ad5640d88963cc744
font_04_sfnt_off0001f056.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F056 2416 bytes
SHA-256: bc5f6d360005b60f4b2c202f8d26ffbedc1af2885bd9bb9c3f18b327eaa7c186
font_05_sfnt_off0001fac0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FAC0 8508 bytes
SHA-256: 8a442cbfd019bc20b83b107d61f7ed9db31990392da9181bdd3c2162c4209aa2
font_06_sfnt_off00020ad1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20AD1 2892 bytes
SHA-256: 910e30d6f0967c809b5e4e8641858feed3847f7cbfc0ca3cccb81a3ef01a7c5b
font_08_sfnt_off00021e38.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21E38 1740 bytes
SHA-256: a24a2d4c00e16ef2815e583633283669afdfb46e3d8c825eda69dc8c22e8d448
font_10_sfnt_off0003cfd3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3CFD3 31360 bytes
SHA-256: 9e8a2f4f9e5c1e0060be5f14a3f552c2cea45f5f0ef77fe08f236e90ad53b451
font_11_sfnt_off0004288d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4288D 90956 bytes
SHA-256: 6e6a245bae1673991db92ede095dcb3d068e66aed5d834e22fca0a9899759053
font_12_sfnt_off0004df79.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4DF79 2864 bytes
SHA-256: de09310d57df2a59182ff000d16c63ddd592a0fbb1268a531b99c852efa2ffe0
font_13_sfnt_off0004e99c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4E99C 2120 bytes
SHA-256: 34627b4c26b8f0eb036c6a3c22f448853491973ba24543e0819dfd15d86508a7
font_14_sfnt_off0004f0f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4F0F8 6360 bytes
SHA-256: 9152631328d8465658c934138bef43b6a17c97413c66ca2c191d60181e53a8ae
font_15_sfnt_off0005011e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5011E 2004 bytes
SHA-256: b6879cd28bc949d313e0e856d09c8cde044284b10a6ac3085b8ee425711915a4