Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0d6f9bc2be78d10…

MALICIOUS

PDF

89.3 KB Created: 2021-04-05 10:22:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3a79e302b64793247c3d586d3da78638 SHA-1: 48a128f9921caabe8ee527df2e9ee823ba053911 SHA-256: b0d6f9bc2be78d10797f139d04623ce33fa3949c3c0409293cdad204e0a4dca1
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that redirects to a site offering movie downloads, likely a lure. The presence of a 'download button' heuristic further supports a phishing or social engineering attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9986

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=alien+vs+predator+full+movie++300mb
    • https://cdn.sqhk.co/litalile/jaighA6/29566995877.pdf
    • https://cdn.sqhk.co/rinilafexowi/sifFwhh/coffin_nails_ombre_yellow.pdf
    • http://paxezimusosesa.scienceontheweb.net/candlestick_patterns_for_day_trading.pdf
    • https://cdn.sqhk.co/luwokiseg/iie8hbE/costumes_for_halloween_male.pdf
    • https://cdn.sqhk.co/datimemovuko/hjjbJ1Z/41670991901.pdf
    • http://beririka.scienceontheweb.net/how_to_wear_a_surgical_mask_with_pleats.pdf
    • https://cdn.sqhk.co/zikufivol/9ojfvPz/98437248430.pdf
    • https://cdn.sqhk.co/tuledapozato/bDIajd0/53067254445.pdf
    • https://cdn.sqhk.co/wazikunal/bvih7Gz/pirate_art_projects_for_toddlers.pdf
    • http://fanisore.sportsontheweb.net/dark_souls_2_design_works_review.pdf
    • http://wivevadevenumet.mywebcommunity.org/pathophysiology_textbook_download.pdf
    • http://dorugatutaxovi.scienceontheweb.net/nafawobelurepenofogiwi.pdf
    • http://tadurarawi.mypressonline.com/berlin_lonely_planet_download.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/e1617057-0fef-4752-ab73-f662c943d787/nespresso_aeroccino_plus.red_light_blinking.pdf
    • http://gixopiv.onlinewebshop.net/best_fitbit_versa_lite_watch_faces.pdf
    • https://uploads.strikinglycdn.com/files/048e8306-9f1a-4a8a-8efd-0b1b193b85b0/81665973203.pdf
    • https://uploads.strikinglycdn.com/files/2b38e105-7694-425b-beb8-eb54b5d9b169/guitar_chords_songs_for_beginners_hindi.pdf
    • http://fojakosi.atwebpages.com/among_the_impostors_chapter_1_summary.pdf
    • https://uploads.strikinglycdn.com/files/a980b0de-e78a-4b13-be01-b7ddb014ece6/20876747426.pdf
    • https://s3.amazonaws.com/lezerawe/dajavarovatavu.pdf
    • http://kususen.myartsonline.com/tenewedarenekamopujixade.pdf
    • https://s3.amazonaws.com/palikuvexake/gegaberezixuwimiw.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f299.bin
8187145963fbf8e0b7977f93bb9cbfc296fb812f6e2b6f40a3c8d31ca5a797a4
pdf-font-stream PDF embedded font (sfnt) at offset 0xF299 6744 bytes
font_01_sfnt_off00010380.bin
cafe2c12b83fe133dc49b174405a64f65556d96360f458ac3595c701564df837
pdf-font-stream PDF embedded font (sfnt) at offset 0x10380 5564 bytes
font_02_sfnt_off0001163f.bin
98b93dda20bf2094931b70888c2c7c01e44614be57eead2cbfadfe23c23e1af0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1163F 1808 bytes
font_03_sfnt_off00011f28.bin
4a1de45d325d3a32ff8ff1a7b4e61c4132f7f819119afc16b5c080f42420575e
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F28 11572 bytes
font_04_sfnt_off000146ca.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x146CA 4324 bytes