Malicious PDF — malware analysis report

Static analysis result for SHA-256 a7e896e750387a4c…

MALICIOUS

PDF

75.5 KB Created: 2021-03-29 09:00:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 485da5e25f9b5ba272837e2908af88b2 SHA-1: 540fe37b156071e9e64d9c242aa47212d6d30050 SHA-256: a7e896e750387a4cbada71fe846f219c51f96bb7a5c52e856aa9d438248e36a1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The sample is a PDF document that uses a lure related to digital electronics questions to trick users into revealing sensitive information, as indicated by the 'SE_SECRET_RECOVERY_LURE' heuristic. The presence of external URIs and ClamAV detection further supports its malicious nature. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it may exploit PDF vulnerabilities or lead to further malicious content, potentially involving JavaScript execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=digital+electronics+questions+pdf
    • http://distornyup.site/hunger_games_book_series_summaryy6hob.pdf
    • https://cdn.sqhk.co/kekelivig/hs89gcp/4322185412.pdf
    • https://cdn.sqhk.co/konidadelan/eGheZgj/planet_fitness_cancel_membership_letter_template.pdf
    • https://cdn.sqhk.co/kugorazig/KchfHR4/puzzle_3d_bus_harry_potter_leclerc.pdf
    • https://cdn.sqhk.co/vubiwete/AHiview/dibolapaziluwaxuf.pdf
    • https://cdn.sqhk.co/wemorapi/WighlVo/66779406816.pdf
    • https://cdn.sqhk.co/lunemitibojo/lXOFhhE/mixajokepugedaginufali.pdf
    • https://cdn.sqhk.co/ritasuxa/vkfjho5/best_to_do_list_free_app_for_iphone.pdf
    • https://cdn.sqhk.co/zinoliwomi/hjgJcTL/guzuxivudutiveb.pdf
    • https://cdn.sqhk.co/wixakulu/hu0Vjcq/xadusezesogajuzifewilu.pdf
    • https://cdn.sqhk.co/nuxegaxujifo/hiqhcGc/33746091054.pdf
    • https://cdn.sqhk.co/bufutoje/gxXgiVF/allegiant_book_ending.pdf
    • https://cdn.sqhk.co/tinipuded/1w7vNGW/6356708836.pdf
    • http://lighterusb24.site/fejitonibogufi9og7a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wemupajese/gufemokotoninawamimisa.pdf
    • https://s3.amazonaws.com/gupojakami/budibego.pdf
    • https://s3.amazonaws.com/bubeto/jason_stephenson_guided_meditation_manifest.pdf
    • https://s3.amazonaws.com/xifabilejilab/financial_management_report_format.pdf
    • https://s3.amazonaws.com/zarelusipofox/rauf_faik_childhood_official_audio.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea14.bin
57d4379fac96e5a7d00410a47c64e542e5437af4d028338839114e7a2abe8bd2
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA14 5448 bytes
font_01_sfnt_off0000fca9.bin
68570c64df8cc01920819862d5f4c534da54e081cbe4a8c8c168b8d49e833018
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCA9 10528 bytes