Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce1a46aea159d541…

MALICIOUS

PDF

126.7 KB Created: 2021-03-28 21:25:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6194755d5aa90c377213fe6cf3f4f666 SHA-1: 161507cd1eb8315730b71f78e6ae2877720b03b5 SHA-256: ce1a46aea159d541aa2fd240b704e4501e5ae8ec5fc7f1a4f5b1c72991636046
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, indicating a phishing or trojan threat. It contains an embedded URL pointing to 'vilenefex.ru', which is likely part of a phishing campaign. The document body's content, though partially corrupted, suggests a lure related to 'Skam season 1', further supporting a phishing or scamming intent. No scripts were extracted, but the presence of malicious URLs and high detection scores strongly suggest a malicious purpose.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=skam+season+1
    • http://newser.site/excel_sheet_data_validationi4v37.pdf
    • http://vigigelerow.22web.org/nolipegisa.pdf
    • http://sportita.fun/40643860848a5dwd.pdf
    • http://stavki-na-sport.site/40745285983sdufj.pdf
    • https://zagemixawidi.weebly.com/uploads/1/3/1/3/131378918/1981275.pdf
    • https://cdn.sqhk.co/wibononuve/aRidBgh/wallpaper_iphone_ios_12_hd.pdf
    • http://top-agent.ru/bikikigotuzoqzmr.pdf
    • https://zemedefikejo.weebly.com/uploads/1/3/4/0/134040876/xujefekusexi-wasifelebuwafe-dezutafira.pdf
    • http://xukewatamom.22web.org/best_development_company_names.pdf
    • http://musofiron.ru/asarta_butters_principles_of_economics_2nd_editionxc4el.pdf
    • https://cdn.sqhk.co/jotenitix/jkOogdQ/fekibororanavibotizimixu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://ec5c17a1-061e-4a2c-a9e6-b3561ba71229.filesusr.com/ugd/299074_248ec152b2404a7ab8a5b5cb44143100.pdf?index=true
    • https://s3.amazonaws.com/zurovajij/rutaxorowuwevenivowujifu.pdf
    • https://4f640d82-8365-4c22-93d6-dbd3427c3fb0.filesusr.com/ugd/55e8b7_a0e2a20ed1c3419c8318e5a4f5baf103.pdf?index=true
    • http://vupikefugogulup.epizy.com/sql_server_2017_free_offline_installer.pdf
    • https://368051e9-4199-40ea-b9a2-dc6e6f83cb3b.filesusr.com/ugd/6260fe_0960585d4fef4149a02aa3424049c45b.pdf?index=true
    • https://s3.amazonaws.com/wunojipu/vedumobumavopemuxew.pdf
    • http://zirexisa.epizy.com/jelutakelexam.pdf
    • http://wegefidipa.epizy.com/48271723443.pdf
    • https://s3.amazonaws.com/werowibovezoje/mimefo.pdf
    • https://s3.amazonaws.com/liluvad/car_valuation_report_for_insurance.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001b15c.bin
fd0fa45f63f033e143d0110e3411ab8837298ea9e329b15c4258fa1bd1983b9f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B15C 4920 bytes
font_01_sfnt_off0001c212.bin
1f67f8cc4a4118fcbc8a436359403edce04d92bb34599f45b0167ef5e870e2b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C212 14012 bytes