Malicious PDF — malware analysis report

Static analysis result for SHA-256 d150fac3f7712bda…

MALICIOUS

PDF

86.1 KB Created: 2021-03-10 02:02:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 2196e1f0dcc5de8e8d0763ec26b266d9 SHA-1: fe8c7072628f25ff2e09c933f1a333f27cb4ee59 SHA-256: d150fac3f7712bda7cc64cc00746e4b9d885f423ab8113bf207752a84fab62ab
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing or trojan payload. The embedded URL, https://pelibifir.ru/strik?utm_term=cambridge+phrasal+verbs+pdf+download, is likely used to serve the malicious content. Although no scripts were explicitly extracted, the PDF structure and the nature of the URL suggest an attempt to trick the user into downloading a secondary payload, aligning with a phishing attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=cambridge+phrasal+verbs+pdf+download PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4381748/normal_5fda106e26660.pdfIn PDF document text
    • https://cdn.sqhk.co/zegofurop/ePZicF1/spinner_ionic_3.pdfIn PDF document text
    • https://cdn.sqhk.co/givesaxi/hbharqC/vefenebinimaz.pdfIn PDF document text
    • https://cdn.sqhk.co/baxemazisod/PidjgiH/10169473878.pdfIn PDF document text
    • https://cdn.sqhk.co/valujoper/d5jiphj/zumotirogawufiviliz.pdfIn PDF document text
    • http://vashe-zdorovie.xyz/ross_casebookptact.pdfIn PDF document text
    • https://cdn.sqhk.co/zasokolof/uwWibEm/fitonu.pdfIn PDF document text
    • https://cdn.sqhk.co/wizokawoxo/bibnThj/lonagogizodapumewaputu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393883/normal_60123a4ee7ac4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489979/normal_601f2f15943d0.pdfIn PDF document text
    • https://cdn.sqhk.co/sigagegijej/bighiy1/alternative_to_h_band_app.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4453342/normal_600696ec6356b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4370996/normal_6009d0ae53670.pdfIn PDF document text
    • http://wisecredit.info/how_to_turn_on_a_jazzy_scooterg8tae.pdfIn PDF document text
    • https://cdn.sqhk.co/pefevepufi/hgnpybY/fokevafitobemebilixisu.pdfIn PDF document text
    • https://cdn.sqhk.co/tamaladafa/jhigijC/euro_truck_simulator_2_mod_car_download.pdfIn PDF document text
    • https://cdn.sqhk.co/bafesugoguwi/7je8Phi/kawanonalolima.pdfIn PDF document text
    • http://fruitnaturs.space/special_products_and_factoring_examples_with_answersjqzsg.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4445338/normal_5fdd29c9ed0e6.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/dakebesuvum/obsidian_arms_-_ar-15_upper_receiver_vise_block.pdfIn PDF document text
    • https://s3.amazonaws.com/boduxatavepe/kafeziratuxese.pdfIn PDF document text
    • https://s3.amazonaws.com/remuv/chiari_ii_malformation_ultrasound.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fc06.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC06 5652 bytes
SHA-256: ce0ac51fd203f5b93c180e8c485515b8d60d6dbbe1e79a7f534a922960fdbb7a
font_01_sfnt_off00010f1d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10F1D 10832 bytes
SHA-256: 58d034d154877e7f063c8c27d1a9d6375a6ac52ec0744aa2c11ec464840178b6
font_02_sfnt_off00013476.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13476 16080 bytes
SHA-256: 0f592f62031d55fa1d0fb4718f5d067d1987426a283bb2ebc7a28ae7d8d4812e