Malicious PDF — malware analysis report

Static analysis result for SHA-256 a66dba673d1da3f0…

MALICIOUS

PDF

120.5 KB Created: 2021-03-10 05:55:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 67a753c136842e0e17e4508ddbd0c7bd SHA-1: 2f981b81cf8bfe4e1246022d384f7d20c8f9cd9b SHA-256: a66dba673d1da3f0472790957beba5fe178538a380048cd1d8bdf204efb8e500
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL designed to trick the user into visiting a phishing site. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically related to phishing. While no scripts were directly extracted, the presence of embedded URLs and the nature of the PDF suggest it's part of a phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/wix?keyword=nebraska+pride+basketball+tryouts
    • http://erogancolumbia.site/the_girl_with_the_dragon_tattoo_2011_movie_cast28x59.pdf
    • http://rabiwitijif.medianewsonline.com/zanubovinet.pdf
    • http://mitutepoka.medianewsonline.com/lg_air_conditioner_error_code_29.pdf
    • https://cdn.sqhk.co/gotakavapu/oBwJijN/zuwigijixenazo.pdf
    • https://cdn.sqhk.co/ligilitojob/hjVphbU/buzevotuf.pdf
    • http://outputqwvk.space/78551252652a9v1b.pdf
    • http://rafale.store/91252699428slnsq.pdf
    • http://findssldz.xyz/gekikovifobemlzlaw.pdf
    • http://kismyketio.com/rich_dad_poor_dad_free_downloadzzsr3.pdf
    • https://cdn.sqhk.co/tazurusubiz/hbhhugh/flying_flappy_bird_download_chrome.pdf
    • http://wirelessinfo.ru/epsxe_bios_plugins_pack3xjx0.pdf
    • http://hamsterbig.com/where_to_repair_typewriter_near_mektvjj.pdf
    • http://xugilerasifoveg.22web.org/is_there_a_list_of_sins.pdf
    • http://zoompol.xyz/lofupidukeioz36.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://a98f38e8-5810-4fc9-be6a-c3d78c7c4f9f.filesusr.com/ugd/921909_2c960c996042419893195ef4151cebe8.pdf?index=true
    • http://ronojegev.rf.gd/dark_souls_2_scholar_of_the_first_sin_ps4_sale.pdf
    • https://4b4b92a8-4ac5-4030-97d5-af0917f8c077.filesusr.com/ugd/0251f0_0308e69e8160436698d3bd3e9af5a6ab.pdf?index=true
    • http://fuvarijes.atwebpages.com/21996205266.pdf
    • https://bb74f61c-7045-47bf-9a7e-968101ee373e.filesusr.com/ugd/81ef4b_25704513975c44968bafd22a75ab5a48.pdf?index=true
    • https://6b54b0b2-91db-43cc-88c8-bbc4f7e20b37.filesusr.com/ugd/a773aa_b3a3f40eee40423dac17e4404c8fa6ce.pdf?index=true
    • http://zegetafirotazaz.atwebpages.com/hizbul_bahr_ka_wazifa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00019e8f.bin
2d5fa56bc84c65e5a1f7a2286c835b7a325d66c4a5c98b4e8451ef113b9e5129
pdf-font-stream PDF embedded font (sfnt) at offset 0x19E8F 5228 bytes
font_01_sfnt_off0001b06d.bin
ec85d5792387a8eb61244c2c0ebc03a89beb70b4b3bf62af349f6b88af7afd2a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B06D 10536 bytes