Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6ef9fe4cb033221…

MALICIOUS

PDF

89.3 KB Created: 2021-04-08 06:54:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1e3ddb18a7421c6920224b4eb90102a7 SHA-1: a84c3c59820c9f14aad1edff23072d066a9a0b78 SHA-256: d6ef9fe4cb03322184fe54d962bbc50961023c38dd0c5f34b996e6157acd738a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, which is likely used to host a malicious payload or redirect the user to a phishing site. The document body, though heavily obfuscated, suggests a lure related to gaming guides, aiming to trick users into clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=eureka+ffxiv+guide+reddit
    • http://wejowadizabudex.mypressonline.com/10144122304.pdf
    • http://lnstagram-office.com/97817659783voa28.pdf
    • http://elinekici.online/troy_bilt_power_washer_motor_oil780cz.pdf
    • http://devgm.design/divazarnxsoq.pdf
    • http://teatr-art.com/will_there_be_another_beautiful_creatures_moviea58xm.pdf
    • http://mon-cmb.best/38607687659yysip.pdf
    • http://ninuxalezopo.getenjoyment.net/arkansas_learners_permit_passenger_restrictions.pdf
    • http://fakaripeti.xyz/toshiba_regza_42rv535uq7z36.pdf
    • http://andyhong.blog/compool_cva-24_valve_actuator_partsccg29.pdf
    • http://apparentlyopt.com/69850621981n6gjy.pdf
    • http://pasikufopubiwo.mypressonline.com/zunatirupinelexapaw.pdf
    • http://avto-trokot.xyz/dojixigomapisawokobuzeiy3hx.pdf
    • http://copyrightshelpscenters.com/single-step_vector_worksheet_answers6xdf0.pdf
    • http://fumizudo.sportsontheweb.net/materiales_no_metalicos_organicos_e_inorganicos.pdf
    • http://goodsun.space/dilavunuufpt.pdf
    • http://shtancircul.site/79147566904bk3r0.pdf
    • http://bidetoluji.getenjoyment.net/skripsi_jurusan_akuntansi_keuangan.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://roveramo.atwebpages.com/bawajufut.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011c8e.bin
4aaa2a3ce63f83b35f76b4cb8f8af41a3409319c2c0ad4557a4fe5e957cd8b3c
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C8E 5016 bytes
font_01_sfnt_off00012dbe.bin
c897c2e9ff2a9dd59794d0e99d06b2c3b6885259b7c8c47cffe0410a4e986b01
pdf-font-stream PDF embedded font (sfnt) at offset 0x12DBE 12464 bytes