Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5926f050ece1cee…

MALICIOUS

PDF

63.1 KB Created: 2020-11-22 13:22:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8e870ea06047df1e398b542322b4663f SHA-1: d3355b10baf697c365f806054f6e74593dffda0f SHA-256: a5926f050ece1ceeb1860a1b6b4142e74e0f18b2d1ce5320ffce63987949e90f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, appears to be a lure related to an 'upgrade guide'. No scripts were extracted, but the presence of an external URI strongly suggests a malicious intent to redirect the user.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?utm_term=airsoft+p90+upgrade+guide
    • https://cdn-cms.f-static.net/uploads/4411501/normal_5f9572981fd74.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/11ec177a-9131-4f0f-ba7f-b6027cd912ca/ser_hacer_y_tener.pdf
    • https://uploads.strikinglycdn.com/files/bc2b3d16-da3d-4d86-ab22-3a4163440f7b/delana.pdf
    • https://uploads.strikinglycdn.com/files/0f37ee79-6a71-45cc-a876-563effc3e30a/lebepexinoravewasalavi.pdf
    • https://uploads.strikinglycdn.com/files/fbf720e6-0aa8-495e-b1ef-8276788985e1/xizapatob.pdf
    • https://uploads.strikinglycdn.com/files/43b6e632-7262-431f-96ca-65001dd13945/sceptical_essays_bertrand_russell_pd.pdf
    • https://s3.amazonaws.com/ninazarila/87907055662.pdf
    • https://uploads.strikinglycdn.com/files/6a362b39-ba63-41f9-afc4-d1362919e78d/3290040681.pdf
    • https://uploads.strikinglycdn.com/files/49ffc89c-e512-4d4f-b9c1-f7aa539240d7/fabesipiboneguwoxa.pdf
    • https://uploads.strikinglycdn.com/files/53d2fa68-4706-4651-95f5-006e3434f776/tv_guide_cablevision.pdf
    • https://uploads.strikinglycdn.com/files/b3d952d5-dab7-4a55-a88f-3394a751ca82/golden_eagle_ii_radar_operator_s_manual.pdf
    • https://uploads.strikinglycdn.com/files/404cd223-8014-4d3a-acd3-c54e2dbb98ba/2941953869.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ac8a.bin
7990bec2379bec27b076915d852fa76c1c0886316fcac3ac1091060b9448d909
pdf-font-stream PDF embedded font (sfnt) at offset 0xAC8A 5240 bytes
font_01_sfnt_off0000be6b.bin
9f0f2d61567ea0b58fcee698f239fff733b72f91667137c30a536b660efae2a5
pdf-font-stream PDF embedded font (sfnt) at offset 0xBE6B 10332 bytes
font_02_sfnt_off0000e1c1.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1C1 4324 bytes