Malicious PDF — malware analysis report

Static analysis result for SHA-256 d09a90b3c812f48b…

MALICIOUS

PDF

70.0 KB Created: 2021-03-10 09:46:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b56946ec24817362d1796ecdea11ac8c SHA-1: 9ecfeaaa2cbc0228aa9435eb78b7898f748a61d0 SHA-256: d09a90b3c812f48bae923feb1db6522c95f672e61d16e34c7212fb8bf9488de1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://golowaki.ru/award?keyword=canon+lide+120+scanner+pdf', suggesting a lure to a phishing or malware distribution site. The document body, though heavily obfuscated, contains metadata related to 'Canon lide 120 scanner pdf' and 'wkhtmltopdf', reinforcing the lure. No scripts were extracted, but the presence of external URIs and the ML/ClamAV detections strongly suggest a phishing or downloader attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=canon+lide+120+scanner+pdf
    • https://cdn-cms.f-static.net/uploads/4468534/normal_600e902b3b4c2.pdf
    • http://slmit.space/gmaps_for_windows_7kj12s.pdf
    • http://nuxuxavolas.22web.org/final_fantasy_7_strategy_guide_free.pdf
    • http://reduslim-italia.website/zamomazumapuzid4k4es.pdf
    • https://cdn-cms.f-static.net/uploads/4500678/normal_60384aca020c9.pdf
    • https://cdn-cms.f-static.net/uploads/4490371/normal_6044937295ab2.pdf
    • http://copyright-securityx.com/fufetofometapudugoc1061.pdf
    • http://okclub.org/15236211020ah5kt.pdf
    • http://jaraxusej.iblogger.org/9115499655.pdf
    • http://dominis.xyz/beats_studio_price_tagznr4a.pdf
    • http://wiinorama.space/burger_king_menu_specials_todayme0f5.pdf
    • https://cdn-cms.f-static.net/uploads/4417329/normal_6018f24a1c36e.pdf
    • https://static.s123-cdn-static.com/uploads/4411220/normal_5ffc7cf046f88.pdf
    • http://zespodsvetkoy.site/netgear_genie_not_showing_attached_devicescgffb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://sobenikirija.rf.gd/conclusion_for_hotel_internship_report.pdf
    • https://s3.amazonaws.com/mevuzokekenojab/18103183551.pdf
    • https://s3.amazonaws.com/kovilowab/vutarozet.pdf
    • https://s3.amazonaws.com/padosumifubobo/guwigutivojobeko.pdf
    • http://wekidezeze.epizy.com/odia_bhajan_song_namita_agrawal.pdf
    • https://s3.amazonaws.com/dutimajizowa/58481961704.pdf
    • http://dukutogesedu.epizy.com/accountability_and_transparency.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d539.bin
885a3ec49a6259d974a65fcba90e6a940146b0eae1c1cda6d654ad1a909cc11b
pdf-font-stream PDF embedded font (sfnt) at offset 0xD539 5380 bytes
font_01_sfnt_off0000e78c.bin
825d92ec297c71dd98db00202ceccf781bbf196bd33dbcac7d3793f90a1a4a59
pdf-font-stream PDF embedded font (sfnt) at offset 0xE78C 10252 bytes