Malicious PDF — malware analysis report

Static analysis result for SHA-256 c9adb98a435b8688…

MALICIOUS

PDF

88.1 KB Created: 2021-03-24 01:08:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6796d599166b870d03f909145806353d SHA-1: 8db25a7eb2e6b74127e80976e180fd72f41f80f3 SHA-256: c9adb98a435b8688125077d2f80649d61e45b610439e07908f0da22c856eee1a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that masquerades as a firmware update for Sennheiser ew 100 g3 devices, a common social engineering tactic. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware delivery. No scripts were extracted, but the presence of an external URI points to a potential download or redirection to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=sennheiser+ew+100+g3+firmware+update
    • https://cdn-cms.f-static.net/uploads/4462037/normal_601e8d36b1c97.pdf
    • https://static.s123-cdn-static.com/uploads/4385417/normal_5ff3b7d955adf.pdf
    • https://static.s123-cdn-static.com/uploads/4466659/normal_5ff07c9c98264.pdf
    • https://cdn-cms.f-static.net/uploads/4419412/normal_600ed0dec70b9.pdf
    • http://xenejesujotolud.mypressonline.com/christ_healing_evangelical_church_live_stream.pdf
    • https://static.s123-cdn-static.com/uploads/4416656/normal_5fc66d1e834e5.pdf
    • https://cdn-cms.f-static.net/uploads/4450516/normal_603bad2ba031e.pdf
    • http://medilawibume.scienceontheweb.net/kiloxa.pdf
    • https://static.s123-cdn-static.com/uploads/4383804/normal_5ff63a0a34b34.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jukoxisojow/bemonc_training_manual_2017.pdf
    • https://s3.amazonaws.com/masevewi/temufutosukirirenavudap.pdf
    • http://bisodusar.epizy.com/do_underground_dog_fences_work.pdf
    • https://s3.amazonaws.com/vonutavekip/chichester_high_school_sixth_form_open_evening.pdf
    • http://pevuzimoba.rf.gd/bijebegofawuvetamamag.pdf
    • https://s3.amazonaws.com/wotodedaruzuk/11028840137.pdf
    • https://s3.amazonaws.com/kujapomib/16915824111.pdf
    • https://s3.amazonaws.com/dowadotiju/70696688127.pdf
    • https://s3.amazonaws.com/rogugagatuf/affin_hwang_select_bond_fund_factsheet.pdf
    • http://lozekav.epizy.com/tanefupogig.pdf
    • https://s3.amazonaws.com/dupula/downer_edi_limited_annual_report_2019.pdf
    • https://s3.amazonaws.com/vetamedisoz/norutasinovafidubatolerex.pdf
    • http://rafubapon.epizy.com/fevaneso.pdf
    • http://limazajot.rf.gd/905944276.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000104d8.bin
1655e6465d27015ded801225a993f573722ed25e5b1ec8dae63c705937133e94
pdf-font-stream PDF embedded font (sfnt) at offset 0x104D8 4592 bytes
font_01_sfnt_off00011512.bin
024f9a66c4b0a6bca04a5c5fd5d9fcd2ca3fe19df8c5bb179946d2bda7069c86
pdf-font-stream PDF embedded font (sfnt) at offset 0x11512 5976 bytes
font_02_sfnt_off0001295a.bin
1352bf902c3d543359e247c5af1522b5918484f1e97cb57e69beae4bfddf45b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1295A 11384 bytes