Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fcab537a9913eb0…

MALICIOUS

PDF

131.2 KB Created: 2021-05-28 04:44:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 8045a108efe442cd5e9380b46ae694bd SHA-1: 1252110a22cd2c2924a9a6e3909713fa248aae23 SHA-256: 9fcab537a9913eb0f41d91ffe1cbcbfa067c14ec1f3590e5b07aa9100eeaf7b7
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. It uses an urgency-based lure. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/strik?utm_term=birds+papaya+ex+husband+jay PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4402294/normal_5fe31d7024e33.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4459320/normal_605ab50295a12.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4366044/normal_5ffc555c99770.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4496170/normal_5ff69b67bc1a8.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4372985/normal_6010c92c9ab63.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470967/normal_602f80cea5f76.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/615adfa6-4a69-4ad3-b5ef-945e1c00aeaf/analisis_sobre_el_decreto_de_guerra_a_muerte_en_la_guerra_hispanoamericana.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/624b8ee3-6b3c-43ab-b31c-6b0697d47791/zoxajojuzekefifime.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/be25b718-580a-4a80-8ba7-0bc8b231db3b/english_vocabulary_lists_by_topic.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/46134e8c-95ad-4f3c-a4cc-90bc3688ac35/xovopogejididimiw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ce4c1613-081a-4295-af7e-a147ef821d4f/calcul_section_cable_triphas_400v_schneider.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9e2f76b8-9c24-4ee4-8fbd-dcef98094f1c/kotub.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f5fdf335-f516-4285-aef3-9c5964535392/las_venas_abiertas_de_latinoamerica_resumen_por_capitulos.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/51525a81-46e3-466d-a2be-b4b1a945c553/driver_impresora_brother_hl-6180dw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dfac2fba-e66b-4535-b5b6-6f3e63a372af/tesla_model_3_battery_replacement_cost_canada.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/37d8364a-e29c-450b-a769-77865a8dd41f/50973845048.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/64ec9150-f30c-4877-a6cd-121e377c8f99/org_design_for_design_orgs.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0bddf2ee-1cfa-497a-a5e0-8c0beec977aa/what_is_systematic_training.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/da277c2e-5f7e-43a2-b0b2-b46d976d60b9/dig_dug_unblocked_66.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6ba41d49-d902-4656-9dcf-1b7c3b8522fa/35893608348.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eba61ad2-d481-4375-b3e7-3b3e44e5af76/19158134961.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b077c51b-9c61-43e5-9948-1bf9941ae49b/halex_electronic_dartboard_with_cabinet.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001c38d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C38D 5452 bytes
SHA-256: 910f24727d76c2ec92a88afe89192c5414de408a523592501acab9eda162369e
font_01_sfnt_off0001d617.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D617 12360 bytes
SHA-256: 8b343077d9aed07a6462ccf3f37a5c22789b1ce4de90bdacd0c5e85bee9b602c