Malicious PDF — malware analysis report

Static analysis result for SHA-256 c74a21921b70a590…

MALICIOUS

PDF

170.0 KB Created: 2021-05-29 21:47:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 61e30eeb12e655f63409ce926057fb09 SHA-1: 82fb28efb832f79f311501bde88cc63304e4417e SHA-256: c74a21921b70a590d37e4f5914194515561a9e690814a99e66e8056d08b3a33f
176 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF document contains heuristics indicating it is malicious and has been flagged by a machine learning classifier. It includes an external URI and embedded URLs, with one prominent URL being 'https://seumenha.ru/strik?utm_term=amharic+power+geez+free+download'. The document also exhibits lures related to clipboard command execution and remote support tools, suggesting an attempt to trick the user into performing actions that would compromise their system or facilitate fraud. No scripts were extracted, but the combination of lures and external links points to a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9953

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/strik?utm_term=amharic+power+geez+free+download
    • https://bijifejutumaxob.weebly.com/uploads/1/3/1/3/131381781/fc19550c95d.pdf
    • https://static.s123-cdn-static.com/uploads/4394082/normal_5fe2e7c814e6e.pdf
    • https://static.s123-cdn-static.com/uploads/4413563/normal_5fca970b6ce81.pdf
    • https://cdn-cms.f-static.net/uploads/4451039/normal_6037cda2ea3fa.pdf
    • https://zefimaral.weebly.com/uploads/1/3/0/7/130776827/8e0b63cb9.pdf
    • https://static.s123-cdn-static.com/uploads/4391326/normal_5ff33096adb81.pdf
    • https://mivezosikobo.weebly.com/uploads/1/3/1/4/131453246/914401902.pdf
    • https://cdn-cms.f-static.net/uploads/4472764/normal_604649c355625.pdf
    • https://wubinuju.weebly.com/uploads/1/3/4/6/134642725/ad3f105.pdf
    • http://www.typoland.com/http://www.typoland.com/designers/Lukasz_Dziedzic/Copyright
    • http://www.typoland.com/
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/7ce9fa3f-e6cb-4b17-866c-0307802acef8/the_shadow_rising_robert_jordan.pdf
    • https://uploads.strikinglycdn.com/files/36d39845-c984-42b4-a207-1682158324d1/tunuxunim.pdf
    • https://uploads.strikinglycdn.com/files/9c59d366-f337-46e4-ac5d-ab70ab6b768f/96667669382.pdf
    • https://uploads.strikinglycdn.com/files/6d5a2a00-43dd-460a-976e-27b61efb9739/lord_of_the_rings_return_of_the_king_extended_version_length.pdf
    • https://uploads.strikinglycdn.com/files/63095c96-4a55-4b96-8bf4-ef7780d4f3dd/how_to_make_a_hexaflexagon_template.pdf
    • https://uploads.strikinglycdn.com/files/4b2a52c7-4fe8-4831-a559-fd8f2c29e2cb/federalists_and_anti_federalists_worksheet_answers.pdf
    • https://uploads.strikinglycdn.com/files/20cdc1ef-711f-4d5d-8186-d0cf62a0062d/platicas_prebautismales_en_guadalajara.pdf
    • https://uploads.strikinglycdn.com/files/503989f4-6f02-4cef-acf6-a0114ed3be0b/oracle_19c_v_views.pdf
    • https://uploads.strikinglycdn.com/files/c29ac49f-dd62-461b-a5b0-3261bbf851f7/sifivowe.pdf
    • https://uploads.strikinglycdn.com/files/3cd8d2b6-fde3-4e81-9148-6e59578ee5ec/bhagavad_gita_quotes_in_english_wallpapers.pdf
    • https://uploads.strikinglycdn.com/files/0fa9995a-4b7f-4f1b-97f8-ddfcc247a6bf/bissell_proheat_2x_revolution_pet_pro_1986_vs_1964.pdf
    • https://uploads.strikinglycdn.com/files/aba5f1e3-a89f-41bb-b0c9-19bb0c2ba301/befuxijizes.pdf
    • https://uploads.strikinglycdn.com/files/a0f6a273-28e7-48da-be74-648b3a1d30d7/briggs_and_stratton_450_oil_drain.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000212fa.bin
fe2a58d0170380cef318cdcc9205513acbb8bfb572e0dc8496ef44241c1b1669
pdf-font-stream PDF embedded font (sfnt) at offset 0x212FA 11916 bytes
font_01_sfnt_off000232e7.bin
50bd8db5ff9a0f03ea6ac0366ab4ff273dceb6ff0c6101ac0faff1fd52ccc92d
pdf-font-stream PDF embedded font (sfnt) at offset 0x232E7 6168 bytes
font_02_sfnt_off00024289.bin
20ce41325981b2201212d9676a2e7295a557093c442c62e7313393c0b55a297d
pdf-font-stream PDF embedded font (sfnt) at offset 0x24289 5524 bytes
font_03_sfnt_off00025542.bin
88a0cbc16974f6983fcc749350452d3db138f8ee14a8683da51a0b17b0eece34
pdf-font-stream PDF embedded font (sfnt) at offset 0x25542 13708 bytes
font_04_sfnt_off00028306.bin
231c0a899c024ad7a5a2e3ebdb881a6a103e100854ceec453a8bcd4e62f5daf4
pdf-font-stream PDF embedded font (sfnt) at offset 0x28306 16408 bytes