Malicious PDF — malware analysis report

Static analysis result for SHA-256 a784926dc01be642…

MALICIOUS

PDF

82.0 KB Created: 2021-03-19 22:55:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3dc3fd814b44c87fa252aa0b321bf894 SHA-1: d3e4c6498f24772a889523b4b481d65fcd88d28e SHA-256: a784926dc01be6424e5302256e210bb2656c62a826022f80a663ffe23ed05fa6
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was identified as malicious by ML classifiers and ClamAV, with a critical heuristic firing for ClamAV detection. It contains an embedded external URI pointing to a suspicious domain, suggesting it's used to redirect users to malicious content. The document body, though heavily obfuscated, contains strings related to 'ukulele tabs pdf download' and the authoring application 'wkhtmltopdf', indicating a lure for potentially unwanted downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=ukulele+tabs+pdf+download
    • http://vexezujuzas.scienceontheweb.net/35103990744.pdf
    • http://kunozoxutokusu.mygamesonline.org/36662485369.pdf
    • https://cdn.sqhk.co/vabalogu/2QWhchi/piviseboxejidalukezotizo.pdf
    • https://cdn.sqhk.co/fipufose/gcCUXGt/get_acc_e55_hints_valve_sequence.pdf
    • https://cdn.sqhk.co/mokevesin/I8ArjjM/funny_sms_hd_ringtone_download_2019.pdf
    • https://cdn.sqhk.co/pekuwalixeso/jjChe21/nadewexajuxeja.pdf
    • https://cdn.sqhk.co/kinubowa/ij4hgwG/tokolikoludotidagaped.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/9c80c4d7-fa86-492d-8b0c-ad078a061488/10834614576.pdf
    • https://uploads.strikinglycdn.com/files/3e111cd4-77c5-41a5-892d-6000d69b97eb/29350231127.pdf
    • https://s3.amazonaws.com/dumupa/nukixodemusagorulazutab.pdf
    • https://s3.amazonaws.com/luramamelolem/vosuzozu.pdf
    • https://s3.amazonaws.com/mefovu/guide_du_dossier_social_tudiant_2019.pdf
    • https://uploads.strikinglycdn.com/files/bb68090b-121a-4ac8-b1fc-aa4fd3d8ad77/zegogula.pdf
    • https://uploads.strikinglycdn.com/files/6ec5fe90-f7c2-406b-8d15-4d9232f94e6f/92000012636.pdf
    • https://uploads.strikinglycdn.com/files/486f90b4-9f6c-43d3-b52a-b3d594b2d45a/how_to_work_an_8mm_projector.pdf
    • https://uploads.strikinglycdn.com/files/a7e0820c-c9db-4a1f-829f-a1d0f4341cea/74270660843.pdf
    • https://uploads.strikinglycdn.com/files/ca5700cf-7b7f-4001-858a-3848381061de/paulo_freire_pedagogia_del_oprimido_frases.pdf
    • https://s3.amazonaws.com/lunojol/janizomixavivulomisupubi.pdf
    • https://s3.amazonaws.com/bulolimepol/crank_ellen_hopkins_quotes.pdf
    • https://uploads.strikinglycdn.com/files/56f69db5-931a-4e82-a5b7-5872acd57382/nordictrack_c900_how_to_unfold.pdf
    • https://uploads.strikinglycdn.com/files/37016b74-adcf-45c1-9303-169a7f69a31b/gopupitaxiwilu.pdf
    • https://uploads.strikinglycdn.com/files/07364941-7b54-488a-b59f-b64cd4045edc/whats_the_best_bread_maker_on_the_market.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eab6.bin
64131fdb93c91ce93049b4bb7c42f9498656144f161503c6dac1c9c8e55913a0
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAB6 5224 bytes
font_01_sfnt_off0000fca8.bin
062f39b25e24879bbef64846e856606371ced800d49dd90ce1e28efa8e2d5727
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCA8 12072 bytes
font_02_sfnt_off000124e7.bin
29910847b90b84b99a52f4f9acaa50e577be6a62d11c10c2c3d2db5b91787bd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x124E7 16252 bytes