Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6056746e1c638b0…

MALICIOUS

PDF

74.0 KB Created: 2021-03-20 00:30:27 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c10396b1604d54cbd2dcf3c850a33f81 SHA-1: eecee5146112e11820ee68ba9bbbaf779b8f72ac SHA-256: c6056746e1c638b065de3ac1ee656b514dc322bb7e2a4cd33907bc97a7906c85
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a lure for "Microsoft rewards points generator" and embeds a URL pointing to a phishing site. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution. No scripts were extracted, but the embedded URI and heuristic firings are sufficient to classify this as a malicious document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=microsoft+rewards+points+generator
    • http://kasyanbeauty.com/flight_simulator_xbox_series_xnftfz.pdf
    • http://nutesane.iblogger.org/17921155262.pdf
    • http://fortuneo.biz/jineloporulzc2bp.pdf
    • http://dkmz3.club/springer_handbook_of_roboticssddal.pdf
    • http://bestita.space/512092542064h6eg.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://jesaruge.epizy.com/ncert_chemistry_book_class_11_free_download_part_2.pdf
    • http://pexabeni.rf.gd/are_old_car_seats_safe.pdf
    • https://s3.amazonaws.com/pugomonapoxuxe/carry_on_jatta_2_songs_all.pdf
    • https://s3.amazonaws.com/gasodamuza/bitadugabekegojegekasal.pdf
    • https://uploads.strikinglycdn.com/files/d17f13d7-7147-4fe4-8514-bed8e36d4361/52456614456.pdf
    • https://9305c775-266c-4126-9ef9-90a5cffee957.filesusr.com/ugd/c3f88d_3aaeb81c04564e3b911a250ad966eecb.pdf?index=true
    • https://cf176ec6-4820-456b-adf9-61e5f06c968f.filesusr.com/ugd/43d598_c753bc3086424a8797c714f47310bb8e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/db5536b3-17da-4173-931e-049067e34ba7/63160880786.pdf
    • http://gafalifavulix.epizy.com/kubiwidetaje.pdf
    • https://uploads.strikinglycdn.com/files/73b0ffc8-24e0-4bbc-a483-4313648c903b/service_economy_world_history_definition.pdf
    • http://felobiziwikegu.rf.gd/letumokex.pdf
    • https://s3.amazonaws.com/lazolu/autismo_infantil_caracteristicas.pdf
    • https://s3.amazonaws.com/kelageketisefuv/75223529440.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d3a4.bin
67e4a17c6da308e2c2574d04c5b41e542a92709ff74f0460a05d790ea946a2f0
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3A4 5176 bytes
font_01_sfnt_off0000e55d.bin
942a0472e759970a3e99ed7360e98319fc438859554994d96a075722fcda145c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE55D 11036 bytes
font_02_sfnt_off00010b2f.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B2F 4324 bytes