Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f6a9ab98cb4c640…

MALICIOUS

PDF

87.4 KB Created: 2021-04-03 17:51:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bb9a4d8fe84402986b02f9c156e11777 SHA-1: 5015351d9d0ac7db3c85bdfcc112ab46f620b371 SHA-256: 9f6a9ab98cb4c64039d3d41b20524906618e81a7ba9a16b747dd97053e144729
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that is likely used as a lure. Although no scripts were extracted, the PDF structure and the presence of an external URI suggest an attempt to redirect the user to a malicious site, likely for phishing purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/wix?keyword=british+literature+final+exam+study+guide
    • http://gikodarekegov.mywebcommunity.org/50683328782.pdf
    • http://sokixatov.mywebcommunity.org/butterfly_life_cycle_book.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xujitezu/lokavexekivesazug.pdf
    • https://s3.amazonaws.com/wisuw/tewenivosunemomop.pdf
    • https://s3.amazonaws.com/jopomodilamego/titiroratarunodaravi.pdf
    • https://s3.amazonaws.com/fonibinaraj/free_military_ringtones_for_android_phones.pdf
    • https://uploads.strikinglycdn.com/files/0ea4f600-536e-41cf-9dd4-4a33f1afd7dd/luxosudufiwafojubegonif.pdf
    • https://s3.amazonaws.com/zozofufulolig/fdmr_my_name_ringtone_free.pdf
    • https://s3.amazonaws.com/gifiz/57248791010.pdf
    • https://s3.amazonaws.com/fivebo/ley_de_condominios_morelos_2020.pdf
    • http://dafukip.myartsonline.com/why_wont_my_antenna_pick_up_channels.pdf
    • https://s3.amazonaws.com/runuzitexokol/bahubali_1_tamil_video_song_free.pdf
    • https://uploads.strikinglycdn.com/files/2e21dce2-e61f-44d8-98f2-8933ffa35b6a/how_to_install_waves_plugins_fl_studio_20.pdf
    • https://s3.amazonaws.com/feborobegibew/rukemoguguzimararilakuwi.pdf
    • https://s3.amazonaws.com/fukezavazuj/archery_game_online.pdf
    • https://uploads.strikinglycdn.com/files/42b1bcdd-cead-4cbd-85e3-39ba3318b8a7/lirusetumekowuzaxajowifix.pdf
    • https://uploads.strikinglycdn.com/files/76b65b69-d877-4c86-b1c9-dce529c9d500/boy_scouts_of_america_store_atlanta.pdf
    • https://s3.amazonaws.com/lekizopiloref/butternut_squash_lasagne_sheets_recipe.pdf
    • https://uploads.strikinglycdn.com/files/a499a983-2bdf-4ca2-9ee2-cb91ada61cc1/xorilos.pdf
    • https://s3.amazonaws.com/duzexefemosaxe/taylor_gs_mini_instructions.pdf
    • https://s3.amazonaws.com/safago/instagram_carousel_photo.pdf
    • https://s3.amazonaws.com/gulapore/popuxafu.pdf
    • https://s3.amazonaws.com/setigafat/55761492282.pdf
    • https://s3.amazonaws.com/xixonu/is_death_note_season_2_good.pdf
    • https://s3.amazonaws.com/dinigugaxej/xovesizukosaboluwopi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011742.bin
686828d4bde56adb13816c9da743044b0d31fbc099fcc6102ecc9e33ac4cecb5
pdf-font-stream PDF embedded font (sfnt) at offset 0x11742 5540 bytes
font_01_sfnt_off00012a02.bin
25a7ca0ce011cceef2411cc3b7818629a8ec38e09618bcf1c5b55d7d81879fe7
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A02 11060 bytes