Malicious PDF — malware analysis report

Static analysis result for SHA-256 c905161676cd63d8…

MALICIOUS

PDF

71.9 KB Created: 2021-02-23 17:52:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9bc1924b83257d4c62ccf4154bad9a1b SHA-1: b7969d795dbce90016ae93df207325ea894b0bff SHA-256: c905161676cd63d8c812dd000651b7dcd60e33601f311e28b5e2e4afe8452261
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for an external URI pointing to 'maypoin.ru', which is suspicious. ClamAV also detected the file as 'Pdf.Phishing.Trojan'. The document body, though heavily obfuscated, contains text related to 'Epic seven leveling guide 2019', suggesting a lure to trick users into visiting the malicious URL. No scripts were extracted, but the presence of an external URI and the phishing detection strongly indicate a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=epic+seven+leveling+guide+2019
    • http://rekabiw.22web.org/assepsia_e_antissepsia_tcnicas_de_esterilizao.pdf
    • http://zebrait.fun/finding_perimeter_and_area_of_irregular_shapes_worksheetzwhy5.pdf
    • http://universityru.fun/84513317469cgezn.pdf
    • https://wewiruvikaju.weebly.com/uploads/1/3/0/7/130775929/xaxepamubofebidad.pdf
    • https://tojejalunegod.weebly.com/uploads/1/3/2/7/132710717/lajanatelediked.pdf
    • https://cdn.sqhk.co/purorenutuw/rjhxKS1/scary_skins_for_roblox_download.pdf
    • https://cdn.sqhk.co/mezutowede/fA0ghuP/kikine_name_meaning.pdf
    • https://cdn.sqhk.co/loxowopiv/chi9Aar/minecraft_space_survival_modpack.pdf
    • http://montana-media.com/gain_followers_on_ig_appm8nf8.pdf
    • https://cdn.sqhk.co/pajokiman/Z4iggfI/69956089194.pdf
    • https://pizijejubuga.weebly.com/uploads/1/3/4/8/134883891/e0c72.pdf
    • http://winwites.space/how_to_download_dj_seratohv75r.pdf
    • https://luvegiramoki.weebly.com/uploads/1/3/3/9/133986347/sifakinabi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://ronagipesi.rf.gd/qualitative_inquiry__research_design_choosing_among_five_approaches_4th_edition.pdf
    • https://s3.amazonaws.com/dadupawo/19540536000.pdf
    • https://s3.amazonaws.com/sudevejerifu/88611307588.pdf
    • https://s3.amazonaws.com/dukexajuj/talasap.pdf
    • http://zegeridibedile.rf.gd/piano_sheet_music_hallelujah_leonard_cohen_free.pdf
    • http://wumepudefix.rf.gd/64430629982.pdf
    • https://s3.amazonaws.com/fajujiju/oakland_raiders_theme_song_sheet_music.pdf
    • https://s3.amazonaws.com/vogubivajavofu/python_3._5_free_32_bit_windows.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dd3d.bin
ae9e2c19696bd559562fee23456c7da6b51dc2c8974513d562235c51c6898806
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD3D 5432 bytes
font_01_sfnt_off0000efe5.bin
3fea1bd112364e8ea276d44e7b6957293cacbf258ad545b3270a5c124c06945b
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFE5 10124 bytes