Malicious PDF — malware analysis report

Static analysis result for SHA-256 c29f67d612b99477…

MALICIOUS

PDF

73.7 KB Created: 2021-03-28 08:06:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1efe676ba79e23cd92910272e356f31c SHA-1: 8666cc598c8c7886f8f7d5c1ef64688758f89575 SHA-256: c29f67d612b99477e55f2029e61676e224c902d11fbf78cd9702e941c2cf82ff
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains numerous embedded URLs, one of which is directly referenced in the heuristic findings, suggesting a phishing or malware distribution attempt. The document body, though heavily obfuscated, appears to reference 'Ncaa basketball rules pdf', indicating a lure to entice users to click on the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/award?keyword=ncaa+basketball+rules+pdf
    • http://rezokivi.medianewsonline.com/encyclopedia_book.pdf
    • https://static.s123-cdn-static.com/uploads/4408323/normal_5fe1cfd85d266.pdf
    • https://cdn-cms.f-static.net/uploads/4494430/normal_6031bc7a351b8.pdf
    • https://cdn-cms.f-static.net/uploads/4476272/normal_603be4038fb86.pdf
    • http://vivebax.iblogger.org/tan_application_form_2017.pdf
    • http://bebetadiruj.mywebcommunity.org/kotifafebavitereragu.pdf
    • https://static.s123-cdn-static.com/uploads/4413705/normal_5ff44e9345746.pdf
    • https://cdn-cms.f-static.net/uploads/4485436/normal_604024c0d57c1.pdf
    • https://cdn-cms.f-static.net/uploads/4410730/normal_600fb9191fef2.pdf
    • https://cdn-cms.f-static.net/uploads/4455901/normal_6042e127e2877.pdf
    • http://kufowawixapiva.sportsontheweb.net/used_starcraft_islander_boats_for_sale_in_ontario.pdf
    • https://cdn-cms.f-static.net/uploads/4408180/normal_605600c651ea1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zugepoguj.onlinewebshop.net/gujugu.pdf
    • http://salivokeru.epizy.com/45861933115.pdf
    • http://zitaporuzi.rf.gd/99857769327.pdf
    • http://tuxodubikanirod.atwebpages.com/loxepagenimapugasubivaju.pdf
    • http://fevepapowiwed.epizy.com/takes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e205.bin
6d2fa2013a508c006ec79a88906cf50cddb2d13e99e629d33f62da3fc213f611
pdf-font-stream PDF embedded font (sfnt) at offset 0xE205 5324 bytes
font_01_sfnt_off0000f430.bin
223943c4733ab464746abac260493785b86952f9f39ff2645012fcea50eecd81
pdf-font-stream PDF embedded font (sfnt) at offset 0xF430 10952 bytes