Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d88160dd25476b7…

MALICIOUS

PDF

113.3 KB Created: 2021-06-12 09:06:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5a04d243b3aeaa605a63f3e2e534f411 SHA-1: fd02058ef91fba39cc580c7e45d16051c4defea0 SHA-256: 9d88160dd25476b75c769ba937838bf9e98c12aa5f3f105432b5f9efaca39e4b
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a critical heuristic firing for ClamAV detection. An external URI pointing to 'coretry.ru' was extracted, which is highly suspicious. The document body, though heavily obfuscated, contains strings that suggest a lure related to 'Sims 4 cheats mac fill needs', likely a pretext to drive the user to the malicious URL. No scripts were extracted, but the PDF structure and external URI are strong indicators of a phishing or malware delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/pbw?utm_term=sims+4+cheats+mac+fill+needs
    • https://static.s123-cdn-static.com/uploads/4529095/normal_5ff9bd298e591.pdf
    • https://cdn-cms.f-static.net/uploads/4383300/normal_5fda89d51a135.pdf
    • https://cdn-cms.f-static.net/uploads/4407100/normal_6038edafc70d9.pdf
    • https://cdn-cms.f-static.net/uploads/4464303/normal_5fe6734b0b70e.pdf
    • https://static.s123-cdn-static.com/uploads/4476432/normal_5fca7787e61a9.pdf
    • https://cdn-cms.f-static.net/uploads/4530846/normal_5fe8dddf618d7.pdf
    • https://cdn-cms.f-static.net/uploads/4387814/normal_605584e515bc8.pdf
    • https://static.s123-cdn-static.com/uploads/4475729/normal_5ffe80acce1ea.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/08978ec8-bfb7-4e67-86a8-82efb2a74e37/17810473572.pdf
    • http://jisopubo.pbworks.com/f/45370680974.pdf
    • https://uploads.strikinglycdn.com/files/e9c5cff5-d440-4fd5-8e8b-b134cb9d1bc5/78978835339.pdf
    • http://gafuxexosaru.pbworks.com/w/file/fetch/145001646/the_cuckoos_calling_download.pdf
    • https://uploads.strikinglycdn.com/files/522b22ba-469f-44e0-a529-2c1e9000a810/vobike.pdf
    • https://uploads.strikinglycdn.com/files/b9f26c90-7821-4282-b650-2933394ea017/formulas_para_calcular_areas_y_perimetros_de_figuras_geometricas.pdf
    • http://nusometa.pbworks.com/f/dizurasajimoxufeviv.pdf
    • https://uploads.strikinglycdn.com/files/bbb7b284-5d6d-4efa-b5ed-5c66d3ea6e9f/canon_pixma_mx922_reviews.pdf
    • http://tereburokofe.pbworks.com/w/file/fetch/145172901/2838441520.pdf
    • https://uploads.strikinglycdn.com/files/19277d9b-211b-4191-bbd5-4b091a8f9238/sirizoluruva.pdf
    • http://kakexigodelo.pbworks.com/w/file/fetch/144575778/what_is_the_difference_between_convex_and_concave_lens.pdf
    • https://uploads.strikinglycdn.com/files/764d775f-1755-4578-8c50-a93b91636485/different_sexual_orientation_synonyms.pdf
    • https://uploads.strikinglycdn.com/files/57544ece-cd78-40f7-9161-fdf79587088c/pathoma_2018_free.pdf
    • https://uploads.strikinglycdn.com/files/5900c584-4275-4e7f-8327-fdcb39a261a0/68566481393.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000162d2.bin
526c5a2175551476bef9e67e23fc16d118bda5f5d89964818a68e3a853678add
pdf-font-stream PDF embedded font (sfnt) at offset 0x162D2 6476 bytes
font_01_sfnt_off000172d9.bin
61378367bac1bfb79c3e69585fa6f753b21628056cf4e189360023530ce0d413
pdf-font-stream PDF embedded font (sfnt) at offset 0x172D9 5356 bytes
font_02_sfnt_off000184ef.bin
dfab3945eace5ba27be1ad95d63d5142397767eab6bca27773794b33bda2302c
pdf-font-stream PDF embedded font (sfnt) at offset 0x184EF 1796 bytes
font_03_sfnt_off00018d79.bin
5eb6c4027d901a7f487318667b5fe1b9439f4a959683be5978e58cf9a9504ac5
pdf-font-stream PDF embedded font (sfnt) at offset 0x18D79 12600 bytes