Malicious PDF — malware analysis report

Static analysis result for SHA-256 d34ea733b7cbd28b…

MALICIOUS

PDF

91.3 KB Created: 2021-05-30 02:55:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 905ccaa7b84d847e4405092ad1a0ecc6 SHA-1: cf7c878227a3bd2b0744735701f43564db5be147 SHA-256: d34ea733b7cbd28bde95cd89c08b5877df7ff0a7eae6604be51fee99faba43bf
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF file was flagged as malicious by a ML classifier and ClamAV, indicating a high likelihood of malicious intent. The 'SE_CLIPBOARD_COMMAND_LURE' heuristic suggests the document instructs users to copy/paste content into a command-line interface, a common technique for executing downloaded payloads. The embedded URL points to a suspicious domain, likely serving as a distribution point for further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=macbook+pro+keyboard+shortcuts+cheat+sheet+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4445129/normal_606591449b728.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4484126/normal_6044d8c734057.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4373509/normal_60033cdc6dd19.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4450430/normal_6069f88606981.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451028/normal_605174475c25a.pdfIn PDF document text
    • https://rexavinuzuna.weebly.com/uploads/1/3/4/3/134308075/74dd886cb5.pdfIn PDF document text
    • https://bevabuje.weebly.com/uploads/1/3/4/8/134897483/4d74e6f3d1.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4483081/normal_5fc571ed9cdbf.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4473954/normal_5ff08b3ae0795.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/2224429c-4e65-43bc-8469-9dc425b07502/aspiracion_de_secreciones_tecnica_abierta_y_cerrada_en_pediatria.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/48aa6897-8e37-43a1-8ac5-1b95ff471b11/gozanetukubudemakamu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/263d6545-7606-4f26-9526-2e0bee19b1a9/gexozesejujesi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f6fe0783-0ad0-43de-bebd-ba3d180c3dd7/8051511682.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9e35120a-0af9-44fd-8791-e4e243e41500/wepagiboxogiz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/de41fc65-cff8-4a40-887b-07c5869e97d1/is_girlboss_based_on_nasty_gal.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9792a148-3327-4f47-a67c-42c85877c782/what_makes_a_valid_deed.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/49eb1efb-0c52-45f2-9a49-e06a1a842ac1/57332799815.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e81b6f18-f4a7-407d-b57c-0ef3a2209a0e/route_delivery_driver_cover_letter.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/36642f35-427a-4cce-8409-a2f506973a8e/best_equalizer_settings_for_lg_soundbar.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa94653f-bab0-417a-9c4e-9c103fa6308e/27225386427.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a8bddcb5-cd53-4842-888d-9c7b8f69cce1/abstract_reasoning_practice_test_australia_free.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010b7e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10B7E 5520 bytes
SHA-256: fc3b5c6a8cc0b98165be2cf5fdcfedabbf799a8276772db32fc0d8e108e20cff
font_01_sfnt_off00011e4e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11E4E 11764 bytes
SHA-256: 36e73cdb7f7dbe5b5783056ae6644f777ee1938fd60ddafe0b04bec7e63302f3
font_02_sfnt_off000146aa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x146AA 16576 bytes
SHA-256: 899ccc2a6a8bda55742108d06bf2fba8c9fd4862a56bafd7913faffa19ea2976