Malicious PDF — malware analysis report

Static analysis result for SHA-256 af0e0cbef7e2c6fd…

MALICIOUS

PDF

72.0 KB Created: 2021-04-03 00:17:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5bd62bde67f486c58b7c595e46223c03 SHA-1: d78ddc8b5404cfde02c31ee35bc512ec0b4d7cad SHA-256: af0e0cbef7e2c6fdfe9cb1dbbef3e87748940e09d46fe141dcbdd671df5edc9b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that directs users to a site offering game cheats, which is a common lure for phishing attacks. The PDF structure and embedded URI heuristic indicate the primary goal is to redirect the user to a malicious domain.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=jurassic+world+alive+cheats+iphone
    • http://larekew.mywebcommunity.org/acetazolamide_davis.pdf
    • http://wedasuf.getenjoyment.net/75932826989.pdf
    • https://cdn.sqhk.co/zegodoxelob/ejgpgiz/67039800510.pdf
    • http://gosunenibunale.getenjoyment.net/tozekifetafosi.pdf
    • http://xuzerujagojagip.scienceontheweb.net/do_all_adverbs_end_in_ly.pdf
    • http://vumamanepu.sportsontheweb.net/list_of_alloys_and_their_composition.pdf
    • https://cdn.sqhk.co/totimujid/Ygc74RI/bcg_attorney_search_scam.pdf
    • https://cdn.sqhk.co/tabakotodi/fhhVo63/49528893905.pdf
    • https://cdn.sqhk.co/komukopa/icihcgf/ludukotomado.pdf
    • https://cdn.sqhk.co/jisaside/gI0CjfZ/70355262006.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/d6559ae7-2583-44b1-9f3e-731310c51704/how_to_be_a_quick_learner_in_school.pdf
    • http://birukuf.onlinewebshop.net/alternator_wiring_diagram_download.pdf
    • https://uploads.strikinglycdn.com/files/e7792672-bc2b-4314-b526-56b07ee37da8/wahl_cordless_chrome_pro_clipper_kit_boots.pdf
    • http://xujalebarot.epizy.com/chlorhexidine_gluconate_davis_drug_guide.pdf
    • https://uploads.strikinglycdn.com/files/675b9e41-5b65-4883-a817-816ee45076f6/gnostic_gospels_mary_magdalene.pdf
    • http://wavexijazibivat.myartsonline.com/anemia_ferropenica_durante_el_embarazo.pdf
    • https://uploads.strikinglycdn.com/files/3f98310a-4c43-4676-b680-900e841bea90/81727956559.pdf
    • https://uploads.strikinglycdn.com/files/e9babba5-4bb1-470a-84ab-0cc6c2e75101/what_kind_of_battery_does_a_2012_dodge_avenger_take.pdf
    • https://uploads.strikinglycdn.com/files/ac5023b6-5572-47f8-8f9e-6db125383691/how_to_program_a_mitsubishi_remote.pdf
    • http://risuveliki.rf.gd/warhammer_40k_9th_edition_rulebook_price.pdf
    • http://zevesijuduma.atwebpages.com/15485058185.pdf
    • https://uploads.strikinglycdn.com/files/660f99b8-8338-4206-bc7d-426a1b16d4e2/31924395934.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dcc5.bin
d5aa2c17ee2bf6f265b1a4b62322ec8e73a3d4c9ce2a221624986141ea02104e
pdf-font-stream PDF embedded font (sfnt) at offset 0xDCC5 5304 bytes
font_01_sfnt_off0000eeda.bin
f9ab93b8bf0a0944337df0651950ac76323998be3b8fdcd4dff802fd1720efc2
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEDA 10568 bytes