Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab8ccdb49f84e332…

MALICIOUS

PDF

75.5 KB Created: 2021-04-02 15:42:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-24
MD5: a2196f27a6473f30ee4195ca45b9d078 SHA-1: 5068545c4068c9316aa9f0e6e12d84fd0c588f77 SHA-256: ab8ccdb49f84e3327b82d577cca92869c85d3282d5bd623ec3c09f7ad9cef779
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/123?utm_term=apricot+planting+guide PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4426822/normal_5ff76415eb7c3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4470696/normal_5fd63f1669cb1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4412762/normal_5fc8ddd6594eb.pdfIn PDF document text
    • https://navowilupaxit.weebly.com/uploads/1/3/1/3/131381067/451590.pdfIn PDF document text
    • https://xoxumowuna.weebly.com/uploads/1/3/5/9/135964844/5e9276b2c6b867.pdfIn PDF document text
    • http://ponaxamewimenul.sportsontheweb.net/40500054866.pdfIn PDF document text
    • https://bivapere.weebly.com/uploads/1/3/4/6/134689139/kidonotorizepoka.pdfIn PDF document text
    • https://gugozakeku.weebly.com/uploads/1/3/4/5/134588211/supamofonusefek_depodebajilewez_lutowev_jasel.pdfIn PDF document text
    • https://jawogebewo.weebly.com/uploads/1/3/4/3/134369376/sitopagipa.pdfIn PDF document text
    • https://mupexopuwes.weebly.com/uploads/1/3/4/7/134722910/a390ffb379.pdfIn PDF document text
    • https://foregizof.weebly.com/uploads/1/3/4/8/134890581/2407271.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4405903/normal_5fff50bae2548.pdfIn PDF document text
    • https://suludexa.weebly.com/uploads/1/3/5/3/135314517/komenajenagujo_ruxomokokakese_ravad.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4492897/normal_603f296041aa0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/pigolo/migukat.pdfIn PDF document text
    • https://s3.amazonaws.com/wiwamoxamo/arteria_iliaca_primitiva.pdfIn PDF document text
    • https://s3.amazonaws.com/somamere/37857600581.pdfIn PDF document text
    • https://s3.amazonaws.com/jawusawar/www.ugames.com_instructions.asp_daisy_duck.pdfIn PDF document text
    • https://s3.amazonaws.com/xafaxotaful/wapogatawojosuder.pdfIn PDF document text
    • http://bilisedutave.myartsonline.com/the_kingdom_of_god_is_within_you_tolstoy.pdfIn PDF document text
    • https://s3.amazonaws.com/tokatefozude/how_to_add_images_to_a_photo_on_iphone.pdfIn PDF document text
    • https://s3.amazonaws.com/vovopafubipu/us_army_reserve_death_benefits.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb49.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB49 5052 bytes
SHA-256: 524ad9a8ee00e93a6ec57c81355b0321647cbf30aa144f3b6648a9d70a03b53f
font_01_sfnt_off0000fc88.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC88 10804 bytes
SHA-256: 79b5512f627b8d9a261ce049128b1ab0eb4d63478133e7f84c0f146959570481