Malicious PDF — malware analysis report

Static analysis result for SHA-256 a5e6a368fa9e0049…

MALICIOUS

PDF

82.1 KB Created: 2021-03-30 03:38:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bba86f39899ed058c6d39162a6ab8750 SHA-1: ecb7af020fb87894a93c738d89f5195e09f81741 SHA-256: a5e6a368fa9e004929b4bd3eaf3c8c2ec3ec59abe25820ed1fab4dcdde9f6b86
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. The presence of an embedded URL pointing to 'druttle.ru' suggests an attempt to trick the user into downloading further malicious content. The heuristic 'SE_DOWNLOAD_BUTTON' further supports the phishing lure aspect.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=toilet+ek+prem+katha+download+123mkv
    • https://cdn-cms.f-static.net/uploads/4427811/normal_5fdc8871cdeaa.pdf
    • https://pakotoroxup.weebly.com/uploads/1/3/0/8/130815058/satinipibe.pdf
    • http://wunadimizurened.medianewsonline.com/gebaludorepunejali.pdf
    • http://rofuxipof.mywebcommunity.org/paper_cutting_book_contemporary_artists_timeless_craft.pdf
    • http://vivubowi.getenjoyment.net/gst_rate_schedule_for_goods_and_services.pdf
    • https://mipikarekegimo.weebly.com/uploads/1/3/1/6/131606279/bopojekowabagulek.pdf
    • https://japozinoju.weebly.com/uploads/1/3/4/8/134847937/5535355.pdf
    • http://fukijuwevo.getenjoyment.net/86453316799.pdf
    • https://static.s123-cdn-static.com/uploads/4412775/normal_5ff145b24e283.pdf
    • https://cdn-cms.f-static.net/uploads/4365657/normal_605de1272b164.pdf
    • http://gesetaxoxu.sportsontheweb.net/kafkas_tebeir_dairesi.pdf
    • https://buvurujexo.weebly.com/uploads/1/3/6/0/136082217/limigisar.pdf
    • http://wijofotezopadik.medianewsonline.com/xanevibomutevivenomag.pdf
    • https://zulezinema.weebly.com/uploads/1/3/0/7/130776370/dawigizamokoga.pdf
    • http://godotobekof.scienceontheweb.net/lubepifexeleke.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://musarozopod.rf.gd/sky_movies_tv_guide_uk.pdf
    • http://segimoto.myartsonline.com/sales_manager_job_description.pdf
    • http://rosunugi.epizy.com/86641949479.pdf
    • http://bilisedutave.myartsonline.com/priority_and_delegation_nclex_book.pdf
    • http://bifovigavij.myartsonline.com/dark_heresy_ascension_fr.pdf
    • http://zanebinelit.rf.gd/armed_forces_community_covenant_grant_application_form.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d86d.bin
21ef080d7d9b64b56db484d9834c86e1fc08f195717f26a85da6d95d2dfa3e32
pdf-font-stream PDF embedded font (sfnt) at offset 0xD86D 5532 bytes
font_01_sfnt_off0000eb2a.bin
d0c9e33916e9e64e42e31bcf0d345f6c2fcd41735b1a34df0119bd0eb1094281
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB2A 3720 bytes
font_02_sfnt_off0000f68e.bin
11184d98a353a5044dae860e18043980c83a8b3bbab6895dd68dad09da4d4c7c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF68E 11084 bytes
font_03_sfnt_off00011c81.bin
860f506bd9721c8284e90d164385804c6bb08d69cdcc5793514650b779e1c5af
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C81 9156 bytes