Malicious PDF — malware analysis report

Static analysis result for SHA-256 a69701863ac3d14c…

MALICIOUS

PDF

78.4 KB Created: 2021-06-06 09:54:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-13
MD5: b80c635752b07a5243cc6a8d4befd8cd SHA-1: 67378be9cbff5e965f315a3093c87b4e2edc8572 SHA-256: a69701863ac3d14ca167d47076ef8ce7c46e14505c96eaa6e852b9b6eb775890
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and ML classifiers indicated a high probability of maliciousness. A heuristic identified an image lure linking to an SEO redirector, specifically `https://coretry.ru/pbw?utm_term=english+download+b1+teacher%2527s+book+pdf+form+5`, which is characteristic of phishing or malware distribution. No scripts were extracted, but the overall structure and heuristics point to a malicious document designed to trick users into downloading further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://coretry.ru/pbw?utm_term=english+download+b1+teacher%2527s+book+pdf+form+5 PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4497687/normal_5ff42dbeeb6dd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475997/normal_604fa7febdf8b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454303/normal_601375e4b1968.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4502906/normal_602ecceb70879.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369173/normal_5fe9a8495357c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454303/normal_605573fabc42e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470400/normal_601d4ee13606d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450728/normal_602e59b071061.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4481990/normal_60256bb7cfae1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4461516/normal_5fd105e0cc262.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4479917/normal_6027db1ab9940.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419413/normal_605af98ab3e54.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4384471/normal_606956f139d9a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4402504/normal_6052d9b9a70e0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c1234391-a9d3-40ee-886a-c3971a3c6c18/32277759327.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cabce302-1ebb-4273-a82c-77a2e2a11a57/what_is_dry_mode_on_mini_split.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/41e93aa3-7725-4889-ab96-b32a404efc3b/25029731176.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4dab9291-5037-40d9-8325-2b66182b9653/98289853681.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc85544b-0a38-4771-adde-3aeb82405225/bethel_music_let_the_king_of_my_heart_lyrics.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d9273938-b785-409a-ae3d-ae8341d87ba4/1758079320.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89d30c20-ff3c-4840-a229-2d65b8275964/brother_ink_lc101_lc103.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f02decf-5d5f-4826-9cee-c5c8329c6539/how_options_trading_works_in_india.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5f31d8b7-665d-4850-8d1a-b64db7dce54d/jobs_for_ma_english_in_pakistan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2e9b400b-3294-4fc2-b5f6-6b03ae66431b/zimofevabosorifigeraki.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d0648a54-393e-4552-a86b-a1a0fc2be5c3/dadurajefitumivafawaf.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f487.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF487 6032 bytes
SHA-256: 8bec4b7676b36b0e352b6eb5397172dbb2b44439535f0bd5bd79fb6d503075a7
font_01_sfnt_off0001090a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1090A 10232 bytes
SHA-256: 0b3c50edfd6fc47b7459dc2e2c41076eaac0dafb84bad3a6556512b1645e2642