Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1f7559f80d2b0d3…

MALICIOUS

PDF

80.2 KB Created: 2021-05-16 14:42:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c2b9b12e5e001b8560121f08ccc7c597 SHA-1: dcc29dc1534e5df212f130e1f112de6e3fabceac SHA-256: b1f7559f80d2b0d3c93f8df7f30962332dae730ae5581710efd92e05bfefd6f1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged by multiple heuristics, including a critical ClamAV detection and an ML classifier, indicating malicious intent. It contains an embedded URL that leads to a suspicious domain, likely serving as a phishing lure. The document body, though heavily obfuscated, appears to be related to APA style references, suggesting a pretext for the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/strik?utm_term=how+do+i+write+references+in+apa+style
    • http://lozaratoz.iblogger.org/gonejuwejonuzudeb.pdf
    • https://cdn.sqhk.co/xorilulog/cjuTxhd/98466941647.pdf
    • http://getiwiviji.22web.org/caruman_kwsp_2020.pdf
    • http://kojijeku.mygamesonline.org/lufenafawagoluwalavirevub.pdf
    • https://cdn.sqhk.co/tatogevi/g9VZoON/learn_russian_fast_and_fun_way.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dazovosugev/jajibowuxazexedipowonido.pdf
    • https://4b5f4e46-8b81-4257-bf39-61fc08ba57b0.filesusr.com/ugd/7ea8bb_4bb68928e2aa4907a567f7a4d73026d6.pdf?index=true
    • http://jokajejuti.atwebpages.com/tuzunuru.pdf
    • https://s3.amazonaws.com/zifilobesumafi/google_chrome_offline_installer_softonic.pdf
    • http://vekoxoke.epizy.com/23078560212.pdf
    • http://gozidonozali.myartsonline.com/why_is_my_elitebook_not_charging.pdf
    • http://nekegax.epizy.com/how_to_think_positive_with_depression.pdf
    • https://d102a0f2-001f-4998-bb0a-88ac30ac05b5.filesusr.com/ugd/771ea4_fc2e8b96efa7403d91f2a4a06fb4b06a.pdf?index=true
    • https://uploads.strikinglycdn.com/files/ea2d11c0-81a9-456c-ba38-84c1dfa58513/21384507835.pdf
    • http://pinavobanokewix.epizy.com/hateful_eight_netflix.pdf
    • https://uploads.strikinglycdn.com/files/da8f1617-94a5-442b-ad1a-29e1022971c2/kujofufo.pdf
    • https://s3.amazonaws.com/fukepez/cyberghost_6_for_windows_7.pdf
    • https://uploads.strikinglycdn.com/files/6ab62b11-9997-49b8-af1e-0bcf3935e457/tidobopasusajizetigomi.pdf
    • https://f55c6975-0091-4942-a106-dc80285e5f9d.filesusr.com/ugd/8a4248_2644b500b7e840efaa2bd8007de3a06c.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fd88.bin
849752fbbed6e43ab766af543cda61a6c063963c9328703480fba18e20cd0107
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD88 5304 bytes
font_01_sfnt_off00010fbc.bin
4babc0f3f76be7bcaec15440d946a33a9bb363de642bba3322cfd1d51a659436
pdf-font-stream PDF embedded font (sfnt) at offset 0x10FBC 10420 bytes