Malicious PDF — malware analysis report

Static analysis result for SHA-256 afec594cbe7be0ac…

MALICIOUS

PDF

138.1 KB Created: 2021-03-25 15:29:05 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8893271bb295eddab1ddf05f0a6e3053 SHA-1: 6e47821f8732f00f2687a36a18b8516903c5c9f7 SHA-256: afec594cbe7be0ac9eb63d434a8a8d1169bb2fb126dfc9cc5b24debdda954c79
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with heuristics indicating the presence of external URIs. The document body, though heavily obfuscated, suggests a lure related to educational worksheets. The embedded URLs, such as 'https://jumiwimov.ru/wix?keyword=roster+method+and+set+builder+notation+worksheet+pdf', are likely used to redirect users to malicious sites for phishing or to download further payloads. No scripts were extracted, but the PDF structure itself facilitates the redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9961

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=roster+method+and+set+builder+notation+worksheet+pdf
    • http://pebifakonek.sportsontheweb.net/wave_interference_worksheet_answers.pdf
    • https://cdn-cms.f-static.net/uploads/4478952/normal_5fd7cf738d655.pdf
    • https://static.s123-cdn-static.com/uploads/4482023/normal_5fe2acc5b67a4.pdf
    • https://static.s123-cdn-static.com/uploads/4470681/normal_5fffea855e825.pdf
    • https://cdn-cms.f-static.net/uploads/4450628/normal_5fd8157ccad6f.pdf
    • http://tuzupibu.scienceontheweb.net/que_es_la_administracion_hotelera.pdf
    • http://taribada.22web.org/python_course_online_in_hindi.pdf
    • https://cdn-cms.f-static.net/uploads/4490542/normal_5fd0e5af3aa93.pdf
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://fedorahosted.org/lohit
    • https://uploads.strikinglycdn.com/files/6d4e1a32-a2ea-407d-8962-79de3dd0aa4e/walmart_auto_center_hours_brooklyn_ct.pdf
    • https://uploads.strikinglycdn.com/files/1bb18b10-4d98-4a35-ae83-767f891de9a2/old_yeller_book_characters.pdf
    • https://uploads.strikinglycdn.com/files/ebccffea-8d6e-49f1-b6d8-39678a574d3f/how_to_use_a_double_sided_waffle_maker.pdf
    • https://uploads.strikinglycdn.com/files/513f106d-24b1-459b-949d-545151ed9969/nagisobexowowokudes.pdf
    • http://xotaferuju.myartsonline.com/mawimunudunowamopub.pdf
    • https://uploads.strikinglycdn.com/files/7abe0473-14c9-40c8-956f-76bf22ae67bc/89150934179.pdf
    • http://kowifojabar.rf.gd/breville_mini_smart_oven_price.pdf
    • https://uploads.strikinglycdn.com/files/16802175-6360-4e8f-be44-d8aae9e029f1/74250885085.pdf
    • http://pujumek.myartsonline.com/what_is_the_fundamental_code_of_jewish_civil_and_canon_law.pdf
    • https://uploads.strikinglycdn.com/files/1886670a-bba7-4d2b-819b-7a2b17e3d9ac/fe_civil_reference_manual.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00015eac.bin
655d69fd347f4873d101678d43946d927d3ba9d47716a6c4e5b0846d28054071
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x15EAC 10476 bytes
stream_006_off0001c6d3.bin
d2316758541fd2218a342b44f3613ef5bb1c499c9c7fa76311868906a5888e02
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1C6D3 24000 bytes
font_00_sfnt_off00011ac8.bin
4ba56d32b27b364c9183cc37212305697cb739652325f1f930444972c45f99bc
pdf-font-stream PDF embedded font (sfnt) at offset 0x11AC8 15060 bytes
font_01_sfnt_off00014c3e.bin
a52b656af2130aeceb4f95789a807f3fbdd5a74ff959432b06a23fb69e5aab6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x14C3E 5464 bytes
font_03_sfnt_off00017c84.bin
2481309ab050ff1c64dbfe9524df4b98f0c044662390e985e1548bcf7efc9780
pdf-font-stream PDF embedded font (sfnt) at offset 0x17C84 27524 bytes
font_05_sfnt_off0001f224.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x1F224 4324 bytes
font_06_sfnt_off00020025.bin
c20b02a33c56e00e3c9723a1b3c9287ba51d2d1da2bbed99fe8a8bb9d0ad294a
pdf-font-stream PDF embedded font (sfnt) at offset 0x20025 6552 bytes