Malicious PDF — malware analysis report

Static analysis result for SHA-256 bef7718b73c2570c…

MALICIOUS

PDF

73.3 KB Created: 2021-03-16 10:22:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0026c7212dfa91b95da216303ae9fec7 SHA-1: e12b45ccf0064df699d5024fb6ad7117704704c1 SHA-256: bef7718b73c2570ca237cf73314f41ff733507780080dd91f47e7589d7212bd7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to 'jacksth.ru', which is likely used to host a malicious payload or phishing page. The document's content, though heavily obfuscated, appears to be a lure related to a 'Stihl bg 86 manual'. No scripts were extracted, but the presence of an external URI and the ML/ClamAV detections strongly indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=stihl+bg+86+manual
    • https://favonewe.weebly.com/uploads/1/3/2/6/132695639/nalanofiwiwagofuxav.pdf
    • https://cdn.sqhk.co/balatexoriv/oeDLJjc/vivadofimosejajew.pdf
    • https://gabonavokelog.weebly.com/uploads/1/3/4/6/134684269/f3170a4.pdf
    • https://cdn.sqhk.co/tesadubozino/dbiUNnu/wubekobe.pdf
    • https://wugabatove.weebly.com/uploads/1/3/5/3/135318753/6806380.pdf
    • http://revadadijavu.22web.org/kigegozoxelamikexivuwa.pdf
    • https://cdn.sqhk.co/gimovitax/h0iaR2k/sadoxarosudalodojufilok.pdf
    • http://triple-doska3.club/assam_police_contractual_answer_key_2019dct7q.pdf
    • http://minuette.me/himno_al_maestro_venezuela_acordesf9ux7.pdf
    • https://cdn.sqhk.co/wesuwajil/aFgchQr/neha_kakkar_all_songs_youtube.pdf
    • http://republvinb.fun/is_denture_adhesive_safe_to_swallow4m37t.pdf
    • http://indital.fun/alien_vpn_apk_uptodown0bj2h.pdf
    • http://lufawobakisi.22web.org/20809219215.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://rupatal.epizy.com/78751867804.pdf
    • http://losamipivoku.epizy.com/fugukura.pdf
    • https://uploads.strikinglycdn.com/files/7634159b-aa8c-41e6-ba5f-2fa08a5b37f4/kubefotinevi.pdf
    • http://pazatirademe.rf.gd/34368372563.pdf
    • https://uploads.strikinglycdn.com/files/f40c0290-66e5-42d6-8505-cb5438ac23b9/what_is_my_self_love_language.pdf
    • http://gewumene.epizy.com/dusuji.pdf
    • http://doroxokile.epizy.com/pumir.pdf
    • https://uploads.strikinglycdn.com/files/7ca5b9d1-ac42-460e-9a46-1819f261b6b0/briggs_and_stratton_vanguard_16_hp_vertical_engine_oil_capacity.pdf
    • http://zefifimagami.epizy.com/a_to_z_odia_song_ringtone.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df89.bin
9ef9bc48f30f310286c38e2053cc6393543ae1b9c541e390b124eef467a33314
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF89 5416 bytes
font_01_sfnt_off0000f1d1.bin
2bda19ee24dcdadc7f6a89857a10164a155aa35b6b11469ff5fc3f25c4704a64
pdf-font-stream PDF embedded font (sfnt) at offset 0xF1D1 10824 bytes