Malicious PDF — malware analysis report

Static analysis result for SHA-256 cde832243e2bd9ed…

MALICIOUS

PDF

78.2 KB Created: 2021-03-28 18:28:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6d7e4eb6b5cafccc1f4914033f347697 SHA-1: 935f7aae2fd46afaa9e4617c6e8debd8e8debde1 SHA-256: cde832243e2bd9ed575e0a6a4ffa84d50e7a379076484c2d5f560dbf3a5e8b34
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI that directs the user to a suspicious URL, disguised as a performance appraisal report sample. This URL is likely intended to deliver a malicious payload or lead to a phishing site. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9964

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/123?utm_term=performance+appraisal+report+sample
    • https://static.s123-cdn-static.com/uploads/4497095/normal_5fc8610bf06fe.pdf
    • https://cdn-cms.f-static.net/uploads/4394082/normal_5fe6a0d04160f.pdf
    • http://vemelaribox.getenjoyment.net/89894656217.pdf
    • https://cdn-cms.f-static.net/uploads/4426953/normal_605dd00c54130.pdf
    • https://cdn-cms.f-static.net/uploads/4366321/normal_6011b630c83a5.pdf
    • https://cdn-cms.f-static.net/uploads/4380083/normal_602422a63fdad.pdf
    • https://cdn-cms.f-static.net/uploads/4457014/normal_6057c9c01a856.pdf
    • https://cdn-cms.f-static.net/uploads/4392647/normal_6018f64bd7ed9.pdf
    • https://static.s123-cdn-static.com/uploads/4445879/normal_5fdf5d175ce48.pdf
    • https://static.s123-cdn-static.com/uploads/4380084/normal_5fe1011f59e42.pdf
    • https://cdn-cms.f-static.net/uploads/4408873/normal_6058d82409912.pdf
    • http://manibupefif.mypressonline.com/what_to_put_on_glue_traps_for_mice.pdf
    • http://ketorebagibof.22web.org/waves_and_electromagnetic_spectrum_worksheet_with_answers.pdf
    • https://cdn-cms.f-static.net/uploads/4481161/normal_603e6e678b652.pdf
    • http://beritox.medianewsonline.com/adjectif_qualificatif_ce1_exercices.pdf
    • https://cdn-cms.f-static.net/uploads/4476282/normal_60501ca87e347.pdf
    • https://static.s123-cdn-static.com/uploads/4413976/normal_5fedfd35de16d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zerufemebokuv.rf.gd/angular_6_form_validation_example.pdf
    • https://s3.amazonaws.com/gelawiweza/simple_past_and_past_perfect_exercises_with_answers.pdf
    • https://s3.amazonaws.com/veledabejufi/mokifawovutenoxarukuma.pdf
    • https://s3.amazonaws.com/gewuwasi/brave_browser_android_flash.pdf
    • https://s3.amazonaws.com/fidobakipivogit/reformat_code_in_visual_studio_code.pdf
    • https://s3.amazonaws.com/bupijila/b._ed_online_form_2019_delhi.pdf
    • http://ropugefax.epizy.com/93422137109.pdf
    • http://zibelasavu.atwebpages.com/how_do_i_invest_in_a_money_market_fund.pdf
    • http://kolofagigetu.epizy.com/emily_blunt_the_devil_wears_prada_quotes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f58c.bin
ceec6c36d141e3ef874eaedec575aae6239785a3a8b9e0687161f18189bf1157
pdf-font-stream PDF embedded font (sfnt) at offset 0xF58C 5164 bytes
font_01_sfnt_off00010701.bin
b614116e701443735e28552b1adb3650199ee51e44d9a90a2a2836c705f96c4b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10701 10572 bytes