Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e06a1a2d9623ba6…

MALICIOUS

PDF

85.4 KB Created: 2021-02-27 15:23:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a2c4168e41dac1c9b82889ac926c251a SHA-1: 7b8f40b31fcb611bff9b250e291c63ed1d3e398a SHA-256: 9e06a1a2d9623ba6935caba09977a7568eb95364f56a6c626dd4d956a06612c3
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that masquerades as information about 'Tomorrowland winter 2020 tickets price', likely to trick users into clicking it. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. While no scripts were directly extracted, the PDF structure and embedded URI heuristic point towards a phishing or credential harvesting attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=tomorrowland+winter+2020+tickets+price
    • http://kurs1.xyz/65955986745vdu7j.pdf
    • http://feelslike35.com/formato_para_mantenimiento_predictivo41k1w.pdf
    • https://cdn.sqhk.co/furugilenu/CT2bjdB/mastercraft_courser_cxt_review.pdf
    • http://taher-tcac.com/essential_elements_clarinet_book_1_free_downloadxkt2h.pdf
    • http://vir-tus.com/49706715514evwjr.pdf
    • http://kulinar2020.site/vidmate_lite_apk_uptodown8hrtf.pdf
    • https://cdn.sqhk.co/jinubodilev/7hgSifb/76993954028.pdf
    • http://kpupnov.pro/ib_biology_ia_word_limitw0gn9.pdf
    • http://b0xberry.online/jegoxelewusujosijakukupegs1u3x.pdf
    • https://cdn.sqhk.co/gubujurit/DjgiaCT/foleserotoropazodifatomiv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kawotexulozax/administrao_financeira_internacional_eiteman.pdf
    • https://s3.amazonaws.com/lijopavexanuse/contemplate_on_someone.pdf
    • https://s3.amazonaws.com/mesixadelomomo/60667065018.pdf
    • https://s3.amazonaws.com/vexeliku/tijep.pdf
    • https://s3.amazonaws.com/tenunud/free_sales_introduction_email_template.pdf
    • https://s3.amazonaws.com/moduxanakuri/87595509151.pdf
    • https://s3.amazonaws.com/xujitezu/android_9_webview_err_cleartext_not_permitted.pdf
    • https://s3.amazonaws.com/xumakomowi/chemistry_notes_o_level.pdf
    • https://s3.amazonaws.com/futamo/bexinulonojixalesubalowa.pdf
    • https://s3.amazonaws.com/gelawiweza/aishwarya_kannada_movie_video_songs.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010229.bin
f43f7286de58a42dd56a062f1d5f359fc16663e5f8c118debf2b9cd7755f318e
pdf-font-stream PDF embedded font (sfnt) at offset 0x10229 3960 bytes
font_01_sfnt_off00011039.bin
ede7b5edd1b5d765e1a6b953f833adec2474e6603b6cc3db83b3a0652d4990b3
pdf-font-stream PDF embedded font (sfnt) at offset 0x11039 5600 bytes
font_02_sfnt_off00012339.bin
9a68f90ddcb21a845a2868f78a6740a5c687b2ba4a12b09defa50aeb547c11e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x12339 10956 bytes