Malicious PDF — malware analysis report

Static analysis result for SHA-256 bffed6b322bcbf74…

MALICIOUS

PDF

82.2 KB Created: 2021-04-07 22:08:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8e3022ca8859dd81bc58908f980e649e SHA-1: 29109439e8ce1bc9c5395e7153c9e679992142fd SHA-256: bffed6b322bcbf74c24527eff4b1c6607e9417dac759afbafe593c037e1f8125
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, specifically identified as 'Pdf.Phishing.Trojan'. The presence of multiple embedded URLs, including one pointing to 'nipisod.ru', suggests an attempt to redirect the user to a malicious site. The document body, though heavily obfuscated, contains references to 'Animal Farm' and PDF download, likely a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=animal+farm+answers+chapter+6
    • https://cdn.sqhk.co/zedazisem/ijja3r8/beautiful_flowers_images_wallpaper_download.pdf
    • https://gatodagimisosog.weebly.com/uploads/1/3/1/3/131379801/xibuj.pdf
    • https://cdn-cms.f-static.net/uploads/4380384/normal_6011b091a571c.pdf
    • http://vykupavto54.ru/game_psp_real_football_20185drum.pdf
    • https://woxumonukoke.weebly.com/uploads/1/3/6/0/136090180/6719287.pdf
    • https://static.s123-cdn-static.com/uploads/4490736/normal_5ff8c6549927f.pdf
    • https://cdn.sqhk.co/vurifozi/QRDhfhb/bionic_hunter_vr_gameplay.pdf
    • http://easterthjg.com/62803488909v8xic.pdf
    • http://policyhelpcenter.com/is_newsmax_tv_free_on_rokulniez.pdf
    • https://cdn-cms.f-static.net/uploads/4452862/normal_60293dad9c488.pdf
    • http://freud.icu/zaxiwiletal03n8y.pdf
    • http://zavarivaemvmeste.ru/risk_assessed_management_plan_liquor_template_qldmra1u.pdf
    • http://richmaya.site/perujeeebrm.pdf
    • https://cdn.sqhk.co/raserijene/bhdiiI5/super_bubble_pop_characters.pdf
    • https://cdn.sqhk.co/vakenuda/je6bGwf/graphic_design_blogspot.pdf
    • https://cdn.sqhk.co/tanusulirava/jeJPPP5/basta_de_lobby.pdf
    • https://debaduvevuw.weebly.com/uploads/1/3/4/3/134383420/getetijabitut_jewunepijetuxez_fuzomexo.pdf
    • https://cdn-cms.f-static.net/uploads/4423732/normal_602d0eef25bfc.pdf
    • https://demijogukif.weebly.com/uploads/1/3/1/3/131382539/558524.pdf
    • https://cdn-cms.f-static.net/uploads/4378604/normal_6028395978f72.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nevowimo/bexisenozesipilogaximal.pdf
    • https://s3.amazonaws.com/rebesudanolo/79743545973.pdf
    • https://s3.amazonaws.com/zepifudoxapo/kebuzunemapigelug.pdf
    • https://s3.amazonaws.com/kabisebax/ge_oven_317b6641p001_manual.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000102b9.bin
6114a0f91a1c54bb2145d5d85964877b0e129e2d1f1afadfe9d45d7c86e456b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x102B9 5488 bytes
font_01_sfnt_off0001154d.bin
88bc9b113d3292ba83a2dff67fd8c4e7c7ee135bce69d1f6d3b7c60579cb4988
pdf-font-stream PDF embedded font (sfnt) at offset 0x1154D 11168 bytes