Malicious PDF — malware analysis report

Static analysis result for SHA-256 c45d082e328c2c3f…

MALICIOUS

PDF

93.3 KB Created: 2021-03-20 00:26:18 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c874e06c87108e0a7051cc1b567bbf17 SHA-1: d736e985726de5b06b3c742d01accdaa9a7b1afb SHA-256: c45d082e328c2c3f89d94fbb67b15a6de68e1097845ce25708613a0df2afa66a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to a suspicious domain, which is likely used to deliver a secondary payload or redirect the user to a phishing site. The document body, though heavily obfuscated, suggests a lure related to a game leveling guide, indicating a phishing or social engineering attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=talonro+rogue+leveling+guide
    • http://rozujed.sportsontheweb.net/bosch_glm_15.pdf
    • https://cdn.sqhk.co/gidenateg/X7Ujhjh/ladybug_castle_runner_3d_game.pdf
    • https://cdn.sqhk.co/xapawavuma/hhCQheE/define_splendor_antonym.pdf
    • https://cdn.sqhk.co/jesupasuzoku/hFkWgeO/toronto_blue_jays_cycling_jersey.pdf
    • http://bopugafuwu.scienceontheweb.net/operaciones_combinadas_fracciones_4_eso.pdf
    • https://cdn.sqhk.co/pajubopolak/doshaUm/word_crossy_level_6585.pdf
    • https://cdn.sqhk.co/bitomasijelo/49Lhhjh/knights_of_europe_in_the_middle_ages_documentary.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • https://s3.amazonaws.com/mizeteb/1191385824.pdf
    • http://kevusej.epizy.com/rapil.pdf
    • http://karajifaderiwow.epizy.com/baby_laughing_sound_ringtone_free.pdf
    • http://jefamunom.rf.gd/defensa_siciliana_najdorf.pdf
    • https://uploads.strikinglycdn.com/files/d719e328-7a6e-406e-81b3-d9314ee8c964/gixunaperajajusukikorata.pdf
    • http://dogamesesokuj.rf.gd/algorithm_design_tutorial.pdf
    • https://s3.amazonaws.com/rerinago/job_interview_questions_and_answers_for_receptionist.pdf
    • https://uploads.strikinglycdn.com/files/9bdfc326-42b7-4c92-8be0-b4e4c3ea4b90/the_winter_of_our_discontent_first_edition.pdf
    • https://s3.amazonaws.com/tedowafomaru/love_bailey_textbook_of_surgery.pdf
    • http://mugazukadum.onlinewebshop.net/jibefiwidiri.pdf
    • https://s3.amazonaws.com/rerinago/curriculum_development_in_nursing_education_free.pdf
    • https://s3.amazonaws.com/vonusirukete/jp_morgan_chase_bank_levy_department.pdf
    • http://xobibaga.myartsonline.com/heteroside_cardiotonique.pdf
    • http://mabazekow.epizy.com/asm_study_manual_for_exam_fm_14th_edition.pdf
    • https://s3.amazonaws.com/bojafazes/vibivupitinizoruposiwakum.pdf
    • http://bidusibebawuz.onlinewebshop.net/simple_power_electronics_mini_projects.pdf
    • https://uploads.strikinglycdn.com/files/95efa8a0-2202-4993-8ab4-508c6a006514/siroxiluwulupuguveg.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000116cd.bin
fc5036887301ed9e67c03afeb6e23791a2278507cebb589f5930f17604eee95a
pdf-font-stream PDF embedded font (sfnt) at offset 0x116CD 4824 bytes
font_01_sfnt_off0001273f.bin
79fcd056b52efe006d97510b482a45799e61021b13f4b1694451f8a32afb5c2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1273F 8424 bytes
font_02_sfnt_off00013e9f.bin
eb2fab039a55ae331c4be49b671d78d8fa99aea55f88c37ab9c98b4998759ec8
pdf-font-stream PDF embedded font (sfnt) at offset 0x13E9F 11560 bytes