Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6e6eaea5eb6e6c7…

MALICIOUS

PDF

77.3 KB Created: 2021-03-23 20:35:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1fde61e029826b8d44d85515f2acfca7 SHA-1: dba16eaf43b7e0be874f192789aa89f4d1a57804 SHA-256: c6e6eaea5eb6e6c75518b0369816e17a702bd409dc468aee02d54f421c39a88a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing an embedded URI pointing to a suspicious domain, identified as malicious by ML classifiers and ClamAV. The document body, though heavily obfuscated, suggests a lure related to 'Alveolar arterial oxygen gradient pdf'. The presence of an external URI strongly indicates an attempt to redirect the user to a malicious site, likely for phishing or to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/award?keyword=alveolar+arterial+oxygen+gradient+pdf
    • https://cdn.sqhk.co/pazaxefuma/hvmf1WU/subway_bbq_rib_sandwich_review.pdf
    • https://cdn.sqhk.co/nixenexax/aX0VzdJ/power_mp3_player_free_music_downloads_online.pdf
    • https://cdn-cms.f-static.net/uploads/4469860/normal_604967df7d3ea.pdf
    • https://static.s123-cdn-static.com/uploads/4375690/normal_5feccc67058d5.pdf
    • https://cdn-cms.f-static.net/uploads/4443356/normal_6025bf9c63e92.pdf
    • https://cdn.sqhk.co/kupovite/jhahm1E/61970159003.pdf
    • https://cdn.sqhk.co/muwizavo/VieVQhg/nexululesud.pdf
    • https://static.s123-cdn-static.com/uploads/4383930/normal_5fe2005695283.pdf
    • https://cdn.sqhk.co/zenetofuma/fWjdjB8/notonobigilewunarofeduja.pdf
    • http://jazazopito.22web.org/gidulewi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jamuluvuvava/star_trek_movies_streaming_australia.pdf
    • https://s3.amazonaws.com/xonobijikivo/nexoketebiwenopaviwirut.pdf
    • http://pefodajisotavuk.rf.gd/rerasajedilu.pdf
    • http://vuvuvemalazot.epizy.com/97941139248.pdf
    • https://s3.amazonaws.com/ragejufa/ocr_a_level_biology_oxford_textbook.pdf
    • https://s3.amazonaws.com/gagagakigibapo/49532354233.pdf
    • http://kenakazukigixow.rf.gd/mifojororevijadam.pdf
    • https://s3.amazonaws.com/jadere/toperekumilare.pdf
    • https://s3.amazonaws.com/rakabexozu/numobikapefepuwudarag.pdf
    • http://bitezopunofiwu.rf.gd/sharp_microwave_drawer_smd2470as_spec_sheet.pdf
    • https://s3.amazonaws.com/gopifu/uk_tv_guide_now_and_next.pdf
    • https://s3.amazonaws.com/pasawexawinogad/77725561260.pdf
    • http://gamanavaje.epizy.com/la_biblia_latinoamericana_catolica.pdf
    • http://litolutu.rf.gd/6071689820.pdf
    • https://s3.amazonaws.com/gelawiweza/alaipayuthey_lyrics_video_song.pdf
    • https://s3.amazonaws.com/jipowumat/bodijowofepolevol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000edb5.bin
bdcc9de38dbe69fae0808538eca78e16c8cf3d36a9038335c4f835517fa62d66
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDB5 5252 bytes
font_01_sfnt_off0000ffb9.bin
4509b19693f3d173627cc62c2dfd143f56019fdb26f8f8a171c7bca046626a35
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFB9 11588 bytes