Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7600eb6d86ffb2c…

MALICIOUS

PDF

84.2 KB Created: 2021-05-16 11:37:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: abfa493ca2571266f64aec06c0652411 SHA-1: 190cde2fc14c38dfc42c63e565906b6fb5d11c17 SHA-256: b7600eb6d86ffb2c9553d1f9a47f6192ab42010b502ba99d4d845b1d6d95e127
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an external URI pointing to 'zajinet.ru', which is likely part of a phishing or malware distribution scheme. Although no scripts were explicitly extracted, the presence of embedded URLs and the ML detection suggest the document is designed to redirect users to malicious content, potentially for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/strik?utm_term=color+and+light+absorption+experiment
    • https://cdn.sqhk.co/madagijoj/jfa9M9p/dejonafamodebevu.pdf
    • https://cdn.sqhk.co/noperizapewo/d2NMjiD/pacific_navy_fighter_commander_apk_download.pdf
    • https://cdn.sqhk.co/fasisela/hb4vYjj/47398710633.pdf
    • http://circus.market/60684791501l4bg.pdf
    • https://cdn.sqhk.co/vumusokutil/oyPjhyS/jiwug.pdf
    • http://websporizle4.com/pejiwifabidipebetuwaz0cua.pdf
    • https://cdn.sqhk.co/ruzesowasu/58u1Tjj/carrom_board_game_carrom_online_multiplayer.pdf
    • http://xibawipo.22web.org/78517817654.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/farokof/24175053940.pdf
    • http://zetesapoxus.epizy.com/basics_of_sql_server.pdf
    • http://jejomozukiro.rf.gd/57672490497.pdf
    • https://s3.amazonaws.com/lanorolowu/xuweno.pdf
    • http://wavanak.epizy.com/arun_sharma_data_interpretation_8th_edition.pdf
    • https://s3.amazonaws.com/zalomi/best_ecommerce_html_template.pdf
    • http://walazej.rf.gd/el_poder_curativo_de_la_cbala.pdf
    • https://s3.amazonaws.com/falufusu/when_a_single_man_buys_a_house.pdf
    • http://fomuzuzidoduvi.epizy.com/46107504586.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7a2.bin
f5027b0d86b7224415194de563d09e9947e44fbece5cfde337058c4bfec7b1b1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7A2 5392 bytes
font_01_sfnt_off0000f9c4.bin
1db1e740fcc971cbe240f8c9e3401aee50830e4a7a3c195664884f82d53f2b92
pdf-font-stream PDF embedded font (sfnt) at offset 0xF9C4 10716 bytes
font_02_sfnt_off00011e2d.bin
59bd9faf73b945fa4dd601516dbb9186deacf479735410a520c5b6c7f94add4f
pdf-font-stream PDF embedded font (sfnt) at offset 0x11E2D 16184 bytes
font_03_sfnt_off00013354.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x13354 4324 bytes