Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc77eb797d0756c8…

MALICIOUS

PDF

74.5 KB Created: 2021-06-05 15:28:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-23
MD5: da6b5e22249b657f7d3319c395e0d9b3 SHA-1: 72eb66fd1cf0c9f993eac5147a21f32f610b7ed6 SHA-256: bc77eb797d0756c8dbaafbbd3ed863f4305576aca87bcb0abe0c6425f6c53ddf
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/pbw?utm_term=fundamentals+of+fluid+dynamics+7th+edition+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4450040/normal_602f475e380b7.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4493195/normal_5fca6ceab32e1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378604/normal_6052aa4b3aa5f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4482190/normal_6017f71aaa524.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4496812/normal_5fce80200180f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375350/normal_603413dab67b1.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4447252/normal_60484343d600f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367621/normal_606697a12e229.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4377400/normal_5fc9068dd0b08.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370068/normal_602956c44f78e.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/436a4fed-7f20-4626-8061-e6d4e8d83c43/samsung_wireless_lan_adapter_wis09abgn2.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a4cf2f0e-d0d1-4a56-86f4-8fa8e622f952/who_makes_panel_ready_refrigerators.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2872c936-d457-41af-acfe-fe608cc7cdc3/85559663943.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b6a36fdf-9ebe-4793-b83d-9f97c30160f8/keurig_b60_parts_diagram.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c05fc542-d67b-4101-a877-436e5ca86637/taurus_pt111_pro_pistol_review.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/242e6e16-9373-4b97-ad9e-2a5ac33cd731/fishman_aura_spectrum_di_preamp_review.pdfIn PDF document text
    • http://betosaxugawi.pbworks.com/f/how_to_calculate_days_in_power_bi.pdfIn PDF document text
    • http://redejok.pbworks.com/f/85052961677.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/82a70643-0b96-4cff-9815-a0c71d8a93c1/supiridumutofolatomusiv.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a4829db-7e2a-45e4-8e42-77c2f4bd4da8/sharp_alarm_clock_walmart.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3f3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE3F3 5436 bytes
SHA-256: fc6f8610c0b3eb02f02eed0925a078cd35b42e7c9a9d77ada017bf6c993e7b7b
font_01_sfnt_off0000f666.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF666 11080 bytes
SHA-256: 3c546ed2e7921d45e3aa9d3e8043dc4747a00c0ba6cf4c853f0ba9492b92114d