Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d8fdf5ae616c551…

MALICIOUS

PDF

81.3 KB Created: 2021-03-17 19:42:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fbc62d62d02a111f99eaf1fada8af8d5 SHA-1: d8d1c74081d529f330129576776dd504a3cdd52b SHA-256: 9d8fdf5ae616c551ffd9ff993903ff4ea2780d0b4fec63f1140aadba3f8efc69
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to 'soxebez.ru', which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, contains strings related to the embedded URI's apparent purpose, suggesting a lure for software downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=autodesk+maya+2020+pdf+download
    • https://cdn.sqhk.co/fenajobuwer/iXDgdhe/36799824832.pdf
    • https://cdn.sqhk.co/tunuviju/IGighji/space_decor_dream_home_design.pdf
    • https://cdn.sqhk.co/kigaratak/hbS9qdm/47073471928.pdf
    • http://dawexefif.getenjoyment.net/41558183220.pdf
    • https://cdn.sqhk.co/jimumakevaji/eyNsLRe/cash_app_sign_up_on_computer.pdf
    • http://worelimupuvefam.mywebcommunity.org/bolexutibe.pdf
    • http://xiwakaravivomik.scienceontheweb.net/macbeth_movie_script.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/476c939c-7a5d-4960-a88c-9c182e5391c2/how_to_eat_3500_calories_a_day_vegan.pdf
    • https://s3.amazonaws.com/sorapobuk/diy_platform_bed_ideas.pdf
    • https://uploads.strikinglycdn.com/files/c5ea599b-fc86-4ec2-bbce-6d6f7ddabd44/sig_p226_p229_magazine_compatibility.pdf
    • https://uploads.strikinglycdn.com/files/3db4d9dd-a8c4-41a5-b4c3-4b5377b579c7/modelo_de_contrato_de_arrendamiento_de_local_comercial_actualizado_word.pdf
    • https://uploads.strikinglycdn.com/files/b1bdd2d7-b85e-420e-a772-7c95fe442c14/explain_how_cultural_diffusion_occurred_in_mesoamerica.pdf
    • https://uploads.strikinglycdn.com/files/0567a9bb-1b83-45f2-961e-a1ca4014e94e/julian_date_calendar_2017_converter.pdf
    • https://uploads.strikinglycdn.com/files/b71f8000-d673-4459-b236-079dcf39285f/53598675267.pdf
    • https://uploads.strikinglycdn.com/files/8718eb1d-76a5-4d88-a97d-1409b7311955/48116819624.pdf
    • https://uploads.strikinglycdn.com/files/4d57a8cc-5c65-4226-9c45-dac37369d43a/fuser_kit_for_hp_color_laserjet_cp4025.pdf
    • https://uploads.strikinglycdn.com/files/c8827945-262a-4065-8b04-6217d12ebedb/zekakijarikezusajowulava.pdf
    • https://uploads.strikinglycdn.com/files/74bf9b49-92ed-482e-bc2c-462d08dc25d6/what_do_the_numbers_1-10_mean_in_the_bible.pdf
    • https://uploads.strikinglycdn.com/files/624d4998-972f-47d8-a6a1-cf99daab6114/rewemigakexisoluk.pdf
    • https://uploads.strikinglycdn.com/files/48306abb-7750-4fcb-b6bc-622236894c6d/lememage.pdf
    • https://uploads.strikinglycdn.com/files/e13b332b-c553-44f1-b923-c09cb1432f83/cambridge_igcse_chemistry_past_papers_answers.pdf
    • https://s3.amazonaws.com/viwoxuz/taxojowesadezodutujutexa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f09f.bin
4a60b0de14e504e56642ee1733fb4ad050633620d8038ecc9bde5c7b6fea72d8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF09F 5448 bytes
font_01_sfnt_off00010331.bin
d65d174ed5c37d748cbf50fc396657f0705f17893a575744c3c5c11b9e6568e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x10331 11312 bytes
font_02_sfnt_off00012832.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x12832 4324 bytes