Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f623a72b31f94a8…

MALICIOUS

PDF

82.7 KB Created: 2021-03-29 02:30:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 615440251c714202a1081082e51f0980 SHA-1: dd8bc4c14758aacb11d5f0d58164cacbf225de13 SHA-256: 9f623a72b31f94a86c7682d77910aba8097417a840233fe2ccacce0abfd244c3
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by ClamAV as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to host a phishing page or download a secondary payload. The presence of a 'download button' heuristic further supports the phishing lure attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/award?keyword=vnsgu+bcom+books+pdf
    • http://rumulive.iblogger.org/what_happened_to_little_albert_after_the_experiment.pdf
    • http://elinekici.online/aquasource_3_handle_tub_and_shower_faucetdcu1c.pdf
    • http://sportplays.ru/89069885967c8qo6.pdf
    • http://store50off.info/minecraft_flux_b11_free_downloadklllg.pdf
    • http://shoop-fh.ru/wen_56200i_super_quiet_2000-watt_portable_inverter_generator_reviews17j19.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9983aaf0-452e-4f31-88f2-59686ae6ae48/92449773842.pdf
    • https://s3.amazonaws.com/lumixi/batman_vs_superman_comic_book.pdf
    • https://s3.amazonaws.com/bupaxomu/sodekemerosepibewa.pdf
    • http://lakiver.epizy.com/disolventes_prticos_y_aprticos.pdf
    • https://uploads.strikinglycdn.com/files/97ce5a8e-0066-431e-8f44-3a9eef1308c7/pit_bike_parts_for_sale.pdf
    • http://jifakobere.rf.gd/simulacra_and_simulation_summary.pdf
    • https://s3.amazonaws.com/gasodamuza/principales_problemas_economicos_de_mexico_independiente.pdf
    • https://uploads.strikinglycdn.com/files/de059b8b-7128-43ec-965e-33b5f52d0aa5/65492179190.pdf
    • http://kufobidup.epizy.com/asio4all_mac_os_x.pdf
    • https://uploads.strikinglycdn.com/files/6e89d592-fb07-44c1-b8fe-b86ffafd7099/pewijenesu.pdf
    • https://uploads.strikinglycdn.com/files/b16da863-c725-4d9a-bea4-938ce1791fdb/47840057666.pdf
    • https://s3.amazonaws.com/minegikukovel/filmorago_pro_apk_no_watermark_android.pdf
    • https://s3.amazonaws.com/dazifozixawus/baixar_netflix_para_android_8._1.pdf
    • https://uploads.strikinglycdn.com/files/2f9bad93-4b3b-413b-b0d2-cb3fe0d0499a/44096781043.pdf
    • https://s3.amazonaws.com/viboxikuz/nazodexoriteteviletolesu.pdf
    • https://uploads.strikinglycdn.com/files/e5a5c56e-fc15-4f10-ab33-fb950b52cb9e/58466198253.pdf
    • https://uploads.strikinglycdn.com/files/4e470c25-efed-4130-8cd0-5fcf023163b1/muxesazetoni.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed66.bin
e542c0ac0eca07fd09556ed66de39226cd33a34ffc1f57a412c09b83d590a31e
pdf-font-stream PDF embedded font (sfnt) at offset 0xED66 5304 bytes
font_01_sfnt_off0000ff70.bin
07cb003676cb1794b71fbfece44d0aa0141dde687cb8e3bf9c4c90c25f11d8d1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF70 11444 bytes
font_02_sfnt_off000126ab.bin
a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x126AB 16204 bytes