Malicious PDF — malware analysis report

Static analysis result for SHA-256 c482c345466829df…

MALICIOUS

PDF

81.9 KB Created: 2021-03-16 04:57:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bc214e908bde8c8022c53fe38129cd19 SHA-1: 8194505f551d8de838216ac81673b6fde54594a0 SHA-256: c482c345466829df14ace70d7975473ecfcb10ac2c14cd2ddb28147e7b0a8189
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains multiple embedded URLs, with the primary one being https://nipisod.ru/wix?keyword=juventud+divino+tesoro+antonio+s+pedreira. The PDF structure and embedded content suggest it's designed to exploit users by directing them to potentially harmful external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9967

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=juventud+divino+tesoro+antonio+s+pedreira
    • http://alphabitx.com/how_to_sell_training_programs_onlinew8cg2.pdf
    • https://cdn.sqhk.co/belesobikezi/igcifJz/analyzing_literary_elements_worksheets.pdf
    • https://cdn.sqhk.co/xugavizira/bCBiigy/mars_mars_conjunct_synastry.pdf
    • https://cdn.sqhk.co/xusarukave/idnPOOW/crash_racing_game_ps4.pdf
    • http://krepezh.guru/the_brothers_menaechmus_character_analysisjudyr.pdf
    • http://basiditdcf.space/89276190527ym0d8.pdf
    • http://natural-shop.info/gituwoxutidebawiczkl9.pdf
    • https://cdn.sqhk.co/gobikazifelo/hbgghek/47165315432.pdf
    • https://cdn.sqhk.co/netimawifes/jdSgiha/miwom.pdf
    • http://lnstagramlivesupportcenter.com/45651707082kd94p.pdf
    • http://starconflict-game.ru/melesipavubotufs7f74.pdf
    • https://cdn.sqhk.co/karopepagu/ggHjbFY/economist_intelligence_unit_country_reports_archive.pdf
    • https://cdn.sqhk.co/wabasenenem/E7ibOjb/dwight_eisenhower_military_industrial_complex_speech.pdf
    • http://rocketdocs.us/smart_launcher_3_pro_apkpureb235p.pdf
    • http://pipvip.ru/wegetinel2vln1.pdf
    • https://cdn.sqhk.co/wemulekojex/1SGLhdp/curriculum_guide_in_tle_7_cookery.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c06eaa82-8de2-4fe5-b4ff-6fcf09a4655b/gumolagaxip.pdf
    • https://s3.amazonaws.com/veraxawewib/pdf_split_chrome_extension.pdf
    • https://s3.amazonaws.com/fatisake/harry_potter_book_1_release_date.pdf
    • https://s3.amazonaws.com/zuguvoxoki/54121903685.pdf
    • https://s3.amazonaws.com/ribowexulo/vomobubenowoda.pdf
    • https://uploads.strikinglycdn.com/files/cfe32a23-2b7b-4259-8f91-986fb9256a95/nukamivemi.pdf
    • https://s3.amazonaws.com/lososimap/lubanipovupasevenugo.pdf
    • https://uploads.strikinglycdn.com/files/842c38db-0671-42e6-a66a-a4b84658ae99/britax_roundabout_g4.1_manual.pdf
    • https://uploads.strikinglycdn.com/files/15d54e4f-4c42-44e9-8b2c-5b4077b07e38/george_foreman_indoor_grill_recipes.pdf
    • https://uploads.strikinglycdn.com/files/69d49609-e78e-4f99-b2bc-c6212284a85e/03_dodge_durango_slt_plus.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001017a.bin
3cbc79901a2e2bb96b4dab98d09d5b50d26aa4df9148e5cf0ee651a2e5293a95
pdf-font-stream PDF embedded font (sfnt) at offset 0x1017A 4972 bytes
font_01_sfnt_off00011274.bin
f97ef80fe62999f175a1a78fd46d9abd262675f85cef54f6dd4dbf57d26e79a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x11274 12088 bytes