Malicious PDF — malware analysis report

Static analysis result for SHA-256 bce893b2488fb43c…

MALICIOUS

PDF

73.5 KB Created: 2021-05-28 21:06:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: b2531ddc92094bbf4e8f8eff87ef256a SHA-1: c49b64fe3a1eba063a556d53f80257d4377b630e SHA-256: bce893b2488fb43c9863b078da41b7f21be57bd548946cf43df215f4927f3aec
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as Pdf.Phishing.Trojan. The document body, though heavily obfuscated, contains text suggesting a lure related to 'Eal resources free worksheets'. An external URI, https://bologen.ru/123?utm_term=eal+resources+free+worksheets, was extracted, indicating a likely phishing attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/123?utm_term=eal+resources+free+worksheets PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4387419/normal_5ff063b18f6ab.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4378830/normal_603ee6074ce9b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489601/normal_606a8fffa768e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4480389/normal_603c3e7a877fa.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391896/normal_601db245e3bcb.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4464873/normal_5fcdea9ca20a0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4471948/normal_603df11fedf04.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4497697/normal_5fe16edf6f041.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413862/normal_605548decc525.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4472783/normal_603542b16e78b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4422135/normal_5ffa55655d0c0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4458839/normal_60472a6f983d2.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4375342/normal_604a15cb6de6c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/b9a94010-1b94-4097-8edb-a14b6ae1838f/why_is_oil_coming_out_of_my_air_filter_on_my_lawn_mower.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4963a1d6-e492-46ee-b37c-6b2302a0e1b5/dna_base_pairing_worksheet_answer_sheet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c5a15788-3728-49bd-b1bd-f63a46ac42d1/how_do_you_add_roms_to_nds4ios.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/21df2290-4d65-45a8-8dae-34cfe6b725e8/vabizozutufokebege.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/35bbb18f-1f50-4d4b-a317-3ca0d8b5c43b/can_i_take_my_drivers_test_online_in_north_carolina.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0b4a6f52-c864-4a3d-8880-91770e0f37b3/possessive_pronouns_worksheets_for_grade_6.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/02977b53-976c-4fef-80ec-208314707041/xerokivapapodijiparane.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f76da070-4732-46b9-8108-995808e31313/explain_how_animals_protect_themselves_from_their_enemies.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7aca45c9-8329-4b1c-949d-cb9f666af404/free_crochet_pattern_for_giant_granny_square_afghan.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e28f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE28F 5080 bytes
SHA-256: 541bfac30051d9b715604f0ca2c9cf59050d65231a2135030621a876e0942ef2
font_01_sfnt_off0000f3ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF3EC 10828 bytes
SHA-256: e1b6c44ad3adbc40f08af92f9063f6313294f7e51c3fb2c9774f4a67fcd2f61f