Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf34adb4fbfee3bf…

MALICIOUS

PDF

79.7 KB Created: 2021-02-15 06:48:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f96adb0de580d755197286d42c09f7c2 SHA-1: 9472f835893d94e53d4646444c1f772a1494ef67 SHA-256: cf34adb4fbfee3bfd93d541f063eadade48e389fefc644e49735fa27c7c61a64
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs, including one pointing to 'leonvi.ru', suggests the document is designed to redirect users to malicious content or phishing sites. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' indicates the document may be part of a multi-stage attack, potentially instructing users to open a password-protected archive.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=sacrosanct+blue+blood+perks
    • https://cdn.sqhk.co/fefoseto/l0BDgcF/lodotu.pdf
    • https://cdn.sqhk.co/towinomer/chdgfhg/wosobesuvedavutaxo.pdf
    • https://cdn.sqhk.co/lilanoto/j2idsha/zosefepulamasu.pdf
    • https://cdn.sqhk.co/jomububorava/jiDDmM4/oxygen_sensor_socket_size.pdf
    • https://cdn-cms.f-static.net/uploads/4391893/normal_60225a2841cd5.pdf
    • https://cdn.sqhk.co/seponidozit/diegdja/zetezodurixasuta.pdf
    • https://cdn-cms.f-static.net/uploads/4447267/normal_602089ca5df2a.pdf
    • https://static.s123-cdn-static.com/uploads/4426059/normal_5fc8c241c62c6.pdf
    • https://cdn.sqhk.co/wofunukasu/YYhexHK/47681783292.pdf
    • https://cdn.sqhk.co/totimujid/dejdhVN/82169445212.pdf
    • http://pepujolajerikur.66ghz.com/anthem_blue_cross_medicaid_appeal_form.pdf
    • http://zasosidimul.22web.org/html_format_number_output.pdf
    • https://cdn.sqhk.co/petebeki/gihihiI/78319252882.pdf
    • https://cdn.sqhk.co/xonudutixova/il5hjhb/gamer_chat_room.pdf
    • https://cdn.sqhk.co/mugegiduveb/FChczid/strike_force_mod_apk_unlimited_everything.pdf
    • http://ssurll.com/10ctq2
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://kilobawul.rf.gd/bexusexozus.pdf
    • http://varoniwarovez.rf.gd/colliers_office_market_report_q1_2019.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e81f.bin
5c6cf7fb093f87782fee50f68daf0389f8bd30b5c6027788acdc5f2b14c60cb7
pdf-font-stream PDF embedded font (sfnt) at offset 0xE81F 5632 bytes
font_01_sfnt_off0000fb8d.bin
51e2c0b404a3e35c1237838d301f8e345a6da1ff8ed228504b5eeb25de3f21b1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB8D 5372 bytes
font_02_sfnt_off00010dd9.bin
ed01163abceca2a372b06649c0447f5830c563ece33491c58c5c7df67f4df64f
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DD9 10528 bytes