Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba66791a248a121c…

MALICIOUS

PDF

75.8 KB Created: 2021-04-06 13:17:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 28c802ea81c85de1e13073646c649937 SHA-1: f1edceb53e6d5c55e7d4c4c63cb023fc1ac478f6 SHA-256: ba66791a248a121cd9510505043c2d002748b184deb80cfef48023fea9b5a82f
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

The sample is identified as malicious by ClamAV and an ML classifier, and it contains heuristics indicating a browser extension installation lure. The embedded URL https://golowaki.ru/123?utm_term=allahabad+kondapuram+lo+ringtone+song is likely part of the lure, potentially leading to a malicious download or phishing page. While no scripts were explicitly extracted, the PDF structure and lure suggest it's designed to trick users into executing further malicious code, possibly via JavaScript.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/123?utm_term=allahabad+kondapuram+lo+ringtone+song PDF link annotation
    • http://talajudoxuxip.mygamesonline.org/fopirajevewolej.pdfIn PDF document text
    • https://cdn.sqhk.co/zidexamuwela/hiiaujg/nupapafoza.pdfIn PDF document text
    • http://artdebug.site/volupijope7v0pg.pdfIn PDF document text
    • https://cdn.sqhk.co/bezupidokaz/hhjgj3s/tuligutot.pdfIn PDF document text
    • http://discount50it.pro/downloader_private_browser_apkpure36zjl.pdfIn PDF document text
    • http://sdfafq.info/zarawufikubijibakuxemegizzfmi6.pdfIn PDF document text
    • https://cdn.sqhk.co/gilikomow/gcESgdl/vanilla_wow_destruction_warlock_guide.pdfIn PDF document text
    • http://madoxorijegobe.sportsontheweb.net/jibajosatutuvilan.pdfIn PDF document text
    • http://dkshlyap.ru/intracellular_signallingthwvj.pdfIn PDF document text
    • http://penafur.scienceontheweb.net/37659529546.pdfIn PDF document text
    • http://6gusevshop.space/8788988668073bt7.pdfIn PDF document text
    • http://rofogukiluvupu.mygamesonline.org/rajexap.pdfIn PDF document text
    • http://slamelina.website/hackear_juegos_con_apk_editor5sesa.pdfIn PDF document text
    • http://unlockdeals.shop/mba_operations_management_jobs_in_canadaoi6dk.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/vesubodufisi/xipejojur.pdfIn PDF document text
    • https://s3.amazonaws.com/fipijife/hoover_max_extract_not_picking_up_water.pdfIn PDF document text
    • https://s3.amazonaws.com/wutisigila/7544391258.pdfIn PDF document text
    • https://s3.amazonaws.com/mikibetiv/game_bejeweled_3_full_version_gratis.pdfIn PDF document text
    • https://s3.amazonaws.com/vinejivunitego/2008_g35_transmission_fluid_change.pdfIn PDF document text
    • https://s3.amazonaws.com/girilifawuxi/32101384463.pdfIn PDF document text
    • https://s3.amazonaws.com/zidenigad/tunedalusafalomusup.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d866.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD866 6744 bytes
SHA-256: 0eac1552a6a0cc8d6d43e14f5c157d052ff2bf21460314f67a2c213e0a454e63
font_01_sfnt_off0000e94d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE94D 5564 bytes
SHA-256: 1b3789c84b1e630a1d8932d48f612bc59e75404365aef9511f87558458a4e3e0
font_02_sfnt_off0000fc03.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC03 11052 bytes
SHA-256: ecda443537d81028d43c4f7ec7e27191bf55798321252a7bf8e96e826869c643