Malicious PDF — malware analysis report

Static analysis result for SHA-256 d04aec36cd09e6f8…

MALICIOUS

PDF

77.4 KB Created: 2021-03-14 09:44:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 20c4b3548de0f78f962732975943a44a SHA-1: 0c8b3988aa1cc3e05db5f64af118fc30137529ac SHA-256: d04aec36cd09e6f8ddf22c013a78e8295ae706c03c7b6d54068e17b2ae526a11
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to 'bologen.ru', which is likely a phishing lure. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a malicious site, likely for phishing purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=libro+para+selena+con+amor+pdf
    • https://cdn.sqhk.co/rodofusavivi/fjgijgi/elements_massage_prices_spokane.pdf
    • http://xibipumazanepir.iblogger.org/new_tamil_album_songs_in_masstamilan.pdf
    • http://pevojatinolotej.22web.org/what_is_kansas_dust_in_the_wind_about.pdf
    • https://cdn.sqhk.co/binuwaxe/03hd1gd/dexelab.pdf
    • https://cdn.sqhk.co/jejekije/rggLuif/igp_manager_strategy_china.pdf
    • https://cdn.sqhk.co/gofelaxes/hhfhehe/kefotiwojabufexa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://ff19a39e-637c-4fc6-80cc-750024e8dd37.filesusr.com/ugd/d217e2_8ddc0c35d7b542478ef30c6af1b3bfe3.pdf?index=true
    • https://1a6defe7-92a0-4357-8a70-d3bce85d30c9.filesusr.com/ugd/385065_ac4cf83b5a7c4cb98d6878ddd3f72f35.pdf?index=true
    • http://niforubuduxema.epizy.com/cause_and_effect_of_global_warming_worksheet.pdf
    • http://zefuziboveteg.epizy.com/3840716994.pdf
    • https://uploads.strikinglycdn.com/files/fd69f44f-bd2d-4bd4-935e-dee7334ee254/how_to_make_pascal_triangle_in_c.pdf
    • http://botalibinizor.rf.gd/chorale_from_jupiter_piano_sheet_music.pdf
    • https://964beff5-d24f-450a-94e2-fa7e9faef44a.filesusr.com/ugd/61158f_67a39b544b704b34a1531c6bad7a24bc.pdf?index=true
    • http://suraweko.epizy.com/zuwoludinobafiw.pdf
    • http://bogasupi.rf.gd/hug_formation_anesthesie.pdf
    • http://tirimetepuxir.epizy.com/how_do_i_reset_my_trane_nexia_thermostat.pdf
    • http://julajibumomas.rf.gd/present_perfect_tense_worksheet.pdf
    • https://uploads.strikinglycdn.com/files/a0af7714-2298-43d3-9c67-9c0ce8e1265a/fomidimasewibakejuzo.pdf
    • http://funizenobuwuka.epizy.com/doi_file_sang_word.pdf
    • https://uploads.strikinglycdn.com/files/7fe77692-4dbd-4f6b-ae8c-5dfaa95ea8f4/midotaxixejadebenu.pdf
    • https://uploads.strikinglycdn.com/files/98675f4d-34fe-47dd-89e2-4da4ebec977c/how_to_hook_up_astro_a20_to_ps4.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d885.bin
afe74a3062d6ee35f9462d5148353b91a85a0776c962723146ee162c2a4b633d
pdf-font-stream PDF embedded font (sfnt) at offset 0xD885 5384 bytes
font_01_sfnt_off0000eab6.bin
3ed488d8fef86a687c71e3f92e3c1217f11116d0f1e11081d09c91e852167e30
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAB6 12272 bytes
font_02_sfnt_off00011310.bin
e5458d7b6d82539349b17fc4713a17e1381d471255c72d9f8116b7c86e08c443
pdf-font-stream PDF embedded font (sfnt) at offset 0x11310 16168 bytes