Malicious PDF — malware analysis report

Static analysis result for SHA-256 b15ca4c47b8cb16d…

MALICIOUS

PDF

77.1 KB Created: 2021-01-19 18:31:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 50b0390a34b98211a1989559ca0ebb54 SHA-1: 7d1698558c3e7de0828772653f71a19459f1618a SHA-256: b15ca4c47b8cb16d2e4eed5eb83aee6eb5443e400a8dc2cbe49f4427f153e5fe
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. The embedded URL and document body suggest a lure related to Android split screen functionality, aiming to redirect users to a malicious site. While no scripts were explicitly extracted, the PDF structure and external URI firings point towards malicious intent, likely involving the execution of embedded JavaScript or exploitation of PDF vulnerabilities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/aws?utm_term=android+9+split+screen+pixel+3
    • https://cdn.sqhk.co/fujigugi/gdiaoHN/zibofu.pdf
    • https://cdn-cms.f-static.net/uploads/4453734/normal_5fe8d0c539806.pdf
    • https://site-1173987.mozfiles.com/files/1173987/guideposts_writing_contest_2018_winners.pdf
    • https://cdn.sqhk.co/wefopijupe/jwcgcia/wuvixiwaxisemulonufota.pdf
    • https://cdn.sqhk.co/dusivubeleza/gjqIhfS/cut_her_off_in_spanish.pdf
    • https://site-1178817.mozfiles.com/files/1178817/61274830641.pdf
    • https://cdn.sqhk.co/baxorurifina/3gcUhh4/idle_landmarks_apk_mod.pdf
    • https://cdn-cms.f-static.net/uploads/4407304/normal_5fd9b49f8e48d.pdf
    • https://static.s123-cdn-static.com/uploads/4485569/normal_5ff45d2fa9d11.pdf
    • https://site-1172629.mozfiles.com/files/1172629/65441067186.pdf
    • https://site-1168211.mozfiles.com/files/1168211/merge_dragons_event_cloud_keys_toys.pdf
    • https://cdn.sqhk.co/bogulevim/jieOsgc/google_play_music_download_mp3_iphone.pdf
    • https://static.s123-cdn-static.com/uploads/4369191/normal_5feb9f41eecdc.pdf
    • https://site-1192107.mozfiles.com/files/1192107/15780530423.pdf
    • https://cdn.sqhk.co/lamiwifa/dGhdnji/server_rack_cabinet_for_sale.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/paropabaru/janatha_garage_naa_songs_ringtones.pdf
    • https://s3.amazonaws.com/sugaguxagu/60265261300.pdf
    • https://s3.amazonaws.com/rowubunak/10091155000.pdf
    • https://s3.amazonaws.com/mexijegedakol/7437945441.pdf
    • https://s3.amazonaws.com/gotenukevepunin/algebra_2_transformations_rules.pdf
    • https://s3.amazonaws.com/visagogijulep/asterisk_1._4_iso.pdf
    • https://s3.amazonaws.com/gezetega/emotional_intelligence_test_printable.pdf
    • https://s3.amazonaws.com/bitizopovopaso/tivozesijifinevonakedoj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f060.bin
2474d4bd28797a72fca5e057e29a1a36352a514675a02d206b3431efd42acc53
pdf-font-stream PDF embedded font (sfnt) at offset 0xF060 5232 bytes
font_01_sfnt_off00010247.bin
2f9bd7a2529787265e8b0b4cbb838b9ace98440736ef296f97cadf2155055071
pdf-font-stream PDF embedded font (sfnt) at offset 0x10247 10664 bytes