Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbb773a09b44bc33…

MALICIOUS

PDF

79.5 KB Created: 2021-03-18 00:59:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 47959774ff07d1ac186cabb3a32cb7ce SHA-1: e5c451662c88df0f35f61974252fd6c1c8d0bd83 SHA-256: bbb773a09b44bc33f79a9bec791b508f9d3dc0595614d419627cad4a04e73bcc
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to 'soxebez.ru', which is highly suspicious given the ClamAV detection and ML classifier flagging. The document body, though heavily obfuscated, suggests a lure related to a 'cabanellas dictionary pdf'. The presence of embedded URLs and the nature of the ClamAV detection (Pdf.Phishing.Trojan) strongly indicate a phishing or trojan delivery attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=cabanellas+diccionario+pdf
    • https://static.s123-cdn-static.com/uploads/4386605/normal_5ff15bd5c1d2a.pdf
    • http://creditactive.info/xuwasujaninhsjod.pdf
    • http://pexarinolal.mypressonline.com/23669394485.pdf
    • http://idealica-italiaufficiale.site/secure_notes_private_notes_and_listsu8sl4.pdf
    • http://zokazurimila.mygamesonline.org/into_the_wild_chapter_4_timeline.pdf
    • http://wotaxatumumodok.sportsontheweb.net/41081918071.pdf
    • http://tijudiwulewanuw.getenjoyment.net/fender_hot_rod_deluxe_30_watt.pdf
    • http://xijivedijimidip.mygamesonline.org/zifaxisojiv.pdf
    • https://static.s123-cdn-static.com/uploads/4470523/normal_5fc8fd21b40e5.pdf
    • http://parralax.net/c_programming_language_for_beginners_books3nok.pdf
    • http://pafekusiwajida.66ghz.com/gastroparesis_guidelines.pdf
    • http://movoxazukum.22web.org/superdry_jacket_size_guide.pdf
    • http://virivuluk.getenjoyment.net/tapebaniporu.pdf
    • http://xolimaked.iblogger.org/iifa_award_show_2018_free.pdf
    • http://kayikciakademi.com/how_much_does_it_cost_to_remove_car_alarms4vzd.pdf
    • http://ginupedarokuxu.getenjoyment.net/behaviorisme_pavlov.pdf
    • https://cdn-cms.f-static.net/uploads/4469106/normal_601ddf3ee6e8f.pdf
    • http://jijomaj.getenjoyment.net/73173370504.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://nukivamo.myartsonline.com/2505389778.pdf
    • http://nukivamo.myartsonline.com/breadboard_for_beginners.pdf
    • http://mevumum.epizy.com/chiari_1_malformation_and_hydrocephalus.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f7aa.bin
9b7011239da2965e1bd90af7ec9c4c8c596ac03d6667835b191fb45b58944cd7
pdf-font-stream PDF embedded font (sfnt) at offset 0xF7AA 5196 bytes
font_01_sfnt_off00010953.bin
7b9de674e06b40a7d7e3a6109394f2395ce5d55cc1aaafeb02666e627e93a085
pdf-font-stream PDF embedded font (sfnt) at offset 0x10953 12036 bytes