Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6ec423f257879ef…

MALICIOUS

PDF

75.8 KB Created: 2021-03-06 20:00:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 11471005523d5fe2deb4f67fe5298980 SHA-1: be92f21d2737468e7dce2f41e0383cc75c524465 SHA-256: d6ec423f257879ef81993268ad6cf863e8ce0874601b0e25536328872dd3c6ec
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to 'maypoin.ru', which is likely part of a phishing or malware distribution scheme. The document body is heavily obfuscated, but the presence of external URIs and the overall detection suggest an attempt to redirect the user to a malicious site, possibly for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=dust+of+illusion+pathfinder
    • http://okstore.info/26727483866qaqks.pdf
    • http://idealslim-ordina.site/44346010808upj0k.pdf
    • https://cdn.sqhk.co/netimawifes/Vcicyjc/real_racing_3_apk_mod.pdf
    • https://cdn.sqhk.co/tutabalero/Jriijil/jupenufubovu.pdf
    • http://circus.market/apptoko_slap_kings4uej5.pdf
    • https://cdn.sqhk.co/wadelovelo/gyBArwp/zunexabovivuvi.pdf
    • https://cdn.sqhk.co/feduvefas/igJjiJc/rejil.pdf
    • https://cdn.sqhk.co/wodelaganav/9ggghgg/talejawinixifufemolemoja.pdf
    • https://cdn.sqhk.co/nukusigemug/ajeid7Z/star_traders_frontiers_best_ship_weapons.pdf
    • http://avit0.pro/60740636910t5l5a.pdf
    • https://cdn.sqhk.co/pubodegosog/Sgfjgmj/wumedilisekekexedarap.pdf
    • https://cdn.sqhk.co/buzovegom/ievhiij/vintage_1_24_scale_slot_cars_for_sale.pdf
    • https://cdn.sqhk.co/kunimanujage/jYZhg63/logo_maker_design_create.pdf
    • https://cdn.sqhk.co/rikopekela/gihwUM8/guns_mod_for_minecraft_pe_ios.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/20be19c1-4989-47bf-bbd5-dfffb12d2ea9/kejif.pdf
    • https://s3.amazonaws.com/xefezesebusu/the_masque_of_red_death_setting.pdf
    • https://uploads.strikinglycdn.com/files/c295728a-010b-4587-a547-f16c5e4ebc29/putozura.pdf
    • https://s3.amazonaws.com/jenagubadopi/production_drawing_of_spur_gear.pdf
    • https://s3.amazonaws.com/davawina/guide_vert_michelin_alsace.pdf
    • https://s3.amazonaws.com/mupukesunobaga/will_microsoft_flight_sim_be_on_xbox_series_x.pdf
    • https://uploads.strikinglycdn.com/files/667654e7-7fe7-4ca8-8a49-7c07f9d882d3/best_dog_training_electric_collar.pdf
    • https://s3.amazonaws.com/tikoweravisixu/can_you_spotify_songs_without_wifi.pdf
    • https://s3.amazonaws.com/daraniwekamidir/xedefa.pdf
    • https://s3.amazonaws.com/webipejonavuv/manual_testing_interview_questions_and_answers_cognizant.pdf
    • https://s3.amazonaws.com/vinejivunitego/sewumariko.pdf
    • https://s3.amazonaws.com/lebaxa/zomolenu.pdf
    • https://s3.amazonaws.com/sitozi/fallout_1_build_guide.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ee5a.bin
056f522e595faa7e7ab1ea682731a242ba86da294160026cd2a06de49845432d
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE5A 5128 bytes
font_01_sfnt_off0000ffc6.bin
4e0330d0c4f301982b0585804e209ccbabbd334fad87215d28cd819bc0752834
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFC6 9852 bytes