Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2388be0aa3aa0ee…

MALICIOUS

PDF

82.2 KB Created: 2021-03-16 10:53:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-25
MD5: bd41f5d836e88dac7a69c82d9678e4ce SHA-1: d151c7a132ec48738af20c63b068dc395317a253 SHA-256: a2388be0aa3aa0eede17acc55982fdce0d4fd5be59352f4847b88da061c5081c
144 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF document contains a high-severity heuristic indicating it's a lure for phishing, specifically offering a fake antivirus license key. The embedded URL, https://maypoin.ru/wix?keyword=avast+free+antivirus+license+key+offline, is identified as the target of this phishing attempt. The ML classifier strongly flags this PDF as malicious, and ClamAV detection confirms its malicious nature as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=avast+free+antivirus+license+key+offline PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4482012/normal_5fef613dce486.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4409244/normal_6006e65fd8fae.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4379054/normal_5fcbc3592e494.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4382423/normal_604e90eaf2331.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447093/normal_603169157b9e1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421038/normal_601c73dbe4ab4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4471710/normal_60259b27b8bc2.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4376874/normal_5ffa62ef449d2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4424696/normal_600e33886a003.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/wuzalugiseto/progress_report_card_comments_elementary.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/43da275d-70a2-48da-974f-7560669d41b9/how_to_talk_confidently_in_a_meeting.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bc76835b-376c-4b86-9eec-378ba2b09304/science_literacy_warm_up_answer_key_19.pdfIn PDF document text
    • https://s3.amazonaws.com/busutafitufe/peter_handke_veliki_pad.pdfIn PDF document text
    • https://s3.amazonaws.com/xomudufe/charlie_and_the_chocolate_factory_movie_2005_cast.pdfIn PDF document text
    • https://s3.amazonaws.com/fezenur/calculo_ley_80_puerto_rico.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5774233d-e45b-402c-b956-e0b902e8f2c8/bissell_little_green_pro.pdfIn PDF document text
    • https://s3.amazonaws.com/rozebofukixus/lofir.pdfIn PDF document text
    • https://s3.amazonaws.com/satudifin/protein_synthesis_ppt.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/68c9bcf3-caa0-4be2-94a8-9a7919baeb99/52686669609.pdfIn PDF document text
    • https://s3.amazonaws.com/jifedefujodu/lladro_values_guide_uk.pdfIn PDF document text
    • https://s3.amazonaws.com/bodajaku/bajrangbali_images_free.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8b411ece-325a-4819-abd8-9c8936381aac/how_to_memorise_tarot_cards.pdfIn PDF document text
    • https://s3.amazonaws.com/moduxanakuri/i-_10_traffic_report_mississippi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d2a80b2-183a-408b-bb0c-19bb63137a3a/71859010401.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f57e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF57E 4972 bytes
SHA-256: 6abf43df9b4ba39fd713b98bb24ef2828277680d7082a5c6f65efce277e06626
font_01_sfnt_off0001067d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1067D 11228 bytes
SHA-256: d3c0c4bf0687e1867ff855e5bf248cd641638b987c0bf5e956c12e4c1925ffb7
font_02_sfnt_off00012cbb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12CBB 4324 bytes
SHA-256: 9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2