Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2b2065ae11fea36…

MALICIOUS

PDF

76.8 KB Created: 2021-05-03 21:05:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-22
MD5: bf059d867a5045be9a968f9022b6d7be SHA-1: 28c4615e27084c2de7db6843b3eed70fb3c1ba22 SHA-256: c2b2065ae11fea36f37dc33e733fa9448a93d0b7c590d256daab050cd9f3b666
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that directs users to a suspicious domain, likely intended to host further malicious content or phishing pages. The document body, though heavily obfuscated, appears to be a lure related to search queries, reinforcing the phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=how+do+i+use+my+brinkmann+smoker PDF link annotation
    • http://mazanatur.space/nelevuvowunifumuwcd9tu.pdfIn PDF document text
    • http://future-techno.ru/77860881491f1m3j.pdfIn PDF document text
    • http://invitesistem.ru/metric_mania_metric_conversions_answer_key7pfu8.pdfIn PDF document text
    • http://vijuziruzunubiz.iblogger.org/amazing_grace_my_chains_are_gone.pdfIn PDF document text
    • http://hookup671.site/what_is_a_developmental_disability_check_all_that_applytsyw4.pdfIn PDF document text
    • http://zdorovienashevse.xyz/29098252116bx1k.pdfIn PDF document text
    • http://tegekagag.22web.org/augusta_national_course_map.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/bofake/revozuwakiget.pdfIn PDF document text
    • http://pejonoma.epizy.com/88142182386.pdfIn PDF document text
    • http://vunefukovamin.rf.gd/21951601847.pdfIn PDF document text
    • https://s3.amazonaws.com/juzowilipi/philosophy_a_guide_to_happiness_epicurus.pdfIn PDF document text
    • https://s3.amazonaws.com/dinigugaxej/the_hobbit_book_summary_shmoop.pdfIn PDF document text
    • https://s3.amazonaws.com/tibitexil/how_to_write_a_realistic_fiction_story.pdfIn PDF document text
    • http://pimisigejofal.rf.gd/airliners._net_trip_report_lufthansa.pdfIn PDF document text
    • http://vejusin.epizy.com/47446978579.pdfIn PDF document text
    • https://s3.amazonaws.com/wizakokowe/balipijoliv.pdfIn PDF document text
    • http://lobexot.epizy.com/what_is_the_rank_of_india_in_democracy_index_2020.pdfIn PDF document text
    • https://s3.amazonaws.com/pisedij/82041399572.pdfIn PDF document text
    • https://s3.amazonaws.com/wesezuzuvalirik/getazefuruworurewagiboj.pdfIn PDF document text
    • http://nuratijuwatag.rf.gd/4994864416.pdfIn PDF document text
    • https://s3.amazonaws.com/garorowa/6732073431.pdfIn PDF document text
    • https://s3.amazonaws.com/wanasuvedigo/seating_arrangement_questions_and_answers_indiabix.pdfIn PDF document text
    • http://fusizizugunu.epizy.com/construction_site_analysis_report_example.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e1ea.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE1EA 5100 bytes
SHA-256: 1c953818addaf923a5e90719917e0e447dbff9c733fb543aed7aeaeb5e7371fd
font_01_sfnt_off0000f32c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF32C 10780 bytes
SHA-256: e0a075521cb780baf4984f61344efaa86aa272b21b64cbaba2b1b0a6c00d90d6
font_02_sfnt_off000117b8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x117B8 4324 bytes
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34