Malicious PDF — malware analysis report

Static analysis result for SHA-256 abae926f1f14a3b3…

MALICIOUS

PDF

579.6 KB Created: 2021-05-22 20:52:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 010d88516ab73c030d452b032d5e78ed SHA-1: cf024a165ffb0c1b9a3c844ec2a956a0144dcafa SHA-256: abae926f1f14a3b3285ab8dfa464ec9f6a04dc2b07aec1ee2b063c8aeea94ee0
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

The sample is a PDF document that employs a social engineering lure, specifically instructing the user to install a browser extension to view content. This is a common tactic for delivering malware or stealing credentials. The presence of external URIs and the ML classifier's high confidence score further support its malicious nature. No scripts were extracted, but the document's structure and embedded URLs suggest it is designed to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8472

Heuristics 8

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://drafthe.ru/uplcv?utm_term=watch+bts+bon+voyage+season+2+episode+8+eng+sub
    • https://alignerco.com/wp-content/plugins/super-forms/uploads/php/files/4a3598307f54274899dbdd78a0cf41bb/xevuwukepojajatetudazab.pdf
    • https://mszukam.pl/dat//file/86907191668.pdf
    • http://creativeindustries.ru/uploads/userfiles/file/borenirosi.pdf
    • http://accessprecision.com/userfiles/file/masoxufonemafoluripexadev.pdf
    • http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/633e8fe9fdee0a6d73cbabcf7d916cd5/38335701231.pdf
    • http://www.northeastmarquees.com/wp-content/plugins/super-forms/uploads/php/files/6dd650acfd3683bd939f816b8814908b/9328682900.pdf
    • https://aronabritcan.com/userfiles/file/86969717311.pdf
    • https://master.plus/wp-content/plugins/super-forms/uploads/php/files/42c408806f99fba42b4054a2e707b8a7/1612966485.pdf
    • http://www.gametimecatering.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c0c84d08f3---47072332892.pdf
    • http://adaviestransportltd.com/userfiles/file/tidikaz.pdf
    • http://alexlunacoach.com/img/editor/file/65886391369.pdf
    • http://bagumul.com/file_upload/spaw_upload/file/20210510103532.pdf
    • https://www.davidcosz.de/wp-content/plugins/super-forms/uploads/php/files/skftv995fjrgjk4usaeij47udm/jesifobomeburigefaseni.pdf
    • http://elm3rad.comfile/5811031095.pdf
    • https://www.frankreich-ferien.ch/wp-content/plugins/formcraft/file-upload/server/content/files/1608ba7bce4779---juduxojepozigar.pdf
    • https://www.andeanskyline.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074249ab6368---tudogodex.pdf
    • https://socialchangefactory.org/wp-content/plugins/super-forms/uploads/php/files/c63bde79b545acb89ca74a3ad00d0b4e/lipafumidozinogiwupew.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_015_off0008e281.bin
1026353de8f73ca1fdd87ef13642063907daf5c084bb66e0528750767304ea7c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8E281 17300 bytes
font_00_sfnt_off00086f40.bin
84a109ff7bdd45c7ddc63c4feb8917583fcbee4e695333da13cf900c66b478e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x86F40 9360 bytes
font_01_sfnt_off00088dc0.bin
e503c1769620ff180694b951b8b3d2539d883b682bf813a94766993f26586945
pdf-font-stream PDF embedded font (sfnt) at offset 0x88DC0 5848 bytes
font_02_sfnt_off0008a1c4.bin
584d7d14adb08efe215e74c3de82079d268bc821596b1520598abbdff14eb6c7
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A1C4 23264 bytes