Malicious PDF — malware analysis report

Static analysis result for SHA-256 be22eb2c8c5af817…

MALICIOUS

PDF

78.2 KB Created: 2021-03-30 07:16:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ae67bd2a302051f472cb9370576372b5 SHA-1: d23c1539d63dfc18dc115291c98aaf024003403c SHA-256: be22eb2c8c5af817a7430bbd2a713cf6861f84ba4d89b34d10949491bb5ad40b
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic indicating an external URI, specifically 'https://druttle.ru/wix?keyword=parkersburg+police+department+hiring', which is likely a phishing lure. ClamAV also detected this file as 'Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0'. The document body, though heavily obfuscated, suggests a pretext related to job hiring, aligning with phishing tactics.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=parkersburg+police+department+hiring
    • https://cdn-cms.f-static.net/uploads/4479925/normal_60586a44771d2.pdf
    • https://static.s123-cdn-static.com/uploads/4409236/normal_6007eb1c43fc1.pdf
    • https://cdn-cms.f-static.net/uploads/4416939/normal_603210172adbd.pdf
    • http://swiss-family.space/nibotidajxuafn.pdf
    • https://static.s123-cdn-static.com/uploads/4475738/normal_5fdde6c092d42.pdf
    • https://static.s123-cdn-static.com/uploads/4402737/normal_6005ff49d5a3f.pdf
    • https://static.s123-cdn-static.com/uploads/4405459/normal_5fc5e345affbe.pdf
    • https://cdn.sqhk.co/dusaradezat/jcCmhfc/crypto_mining_bot_telegram.pdf
    • https://cdn-cms.f-static.net/uploads/4445119/normal_600dc7d8403ee.pdf
    • https://cdn.sqhk.co/gewewoturila/eCEpYMG/mateziwelefilune.pdf
    • https://cdn-cms.f-static.net/uploads/4456676/normal_6018408536fb6.pdf
    • https://cdn-cms.f-static.net/uploads/4489980/normal_603c14b13abb2.pdf
    • http://itsnat.space/64846860620kwp4x.pdf
    • http://oneplusonemain.xyz/pipe_fishmouth_templateapnvw.pdf
    • https://cdn-cms.f-static.net/uploads/4481527/normal_6041adba77228.pdf
    • https://cdn.sqhk.co/vofonowul/fx7jcgj/33179778513.pdf
    • http://good-production11.site/canon_eos_rebel_xsi_user_manualvsy42.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xoxaneral/99810526221.pdf
    • https://uploads.strikinglycdn.com/files/bc283281-27e3-43d8-8203-f6f397eee8dd/88880940581.pdf
    • https://s3.amazonaws.com/zaxefemebidaz/haunted_house_waiver_form_mckamey_manor.pdf
    • https://uploads.strikinglycdn.com/files/55617fdc-3b53-42e8-84f7-0491b160b3ec/35058959215.pdf
    • https://uploads.strikinglycdn.com/files/a6ad8df6-4353-485f-8f87-4fa2b3a33a6d/kenmore_elite_refrigerator_french_door_spring.pdf
    • https://uploads.strikinglycdn.com/files/9171472c-84a7-482c-8421-5d6e134eb51c/sex_and_the_city_3_date_de_sortie.pdf
    • https://s3.amazonaws.com/wajibile/929266382.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1a1.bin
1129eed6ed5a40891c464680c58bd507172aaf0efd6a8b0c311fa8dab7a87dfc
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1A1 5692 bytes
font_01_sfnt_off000104ca.bin
40c57ca5f7bb8029476991e7497e01067f0dac1280fcdd80da1ef81ee92310df
pdf-font-stream PDF embedded font (sfnt) at offset 0x104CA 11372 bytes