Malicious PDF — malware analysis report

Static analysis result for SHA-256 d949e82093ac66a9…

MALICIOUS

PDF

81.5 KB Created: 2021-03-29 19:31:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eb839ee3f8f4634a8eced724c2d3390d SHA-1: d6d54bbcef14e8f54aaddbdd09d787b679c0aaf0 SHA-256: d949e82093ac66a9b1c93e45bf8df90f47ba69c55f142b2428b2cd328fea1b2f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic indicating an external URI, which points to a URL associated with game cheat searches. This URL is likely used as a lure to direct users to a malicious site. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=world+conqueror+3+unlimited+medals+android
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vovuzize/xufifigovulug.pdf
    • https://s3.amazonaws.com/ronenitevodo/kutemotexukibibowigufus.pdf
    • https://s3.amazonaws.com/sobaketemu/analog_clock_worksheets_grade_2.pdf
    • https://uploads.strikinglycdn.com/files/7af53111-f29d-4e21-81c6-98cb5d3737aa/basic_dutch_grammar_book.pdf
    • https://uploads.strikinglycdn.com/files/6e5560f2-94f0-4747-ac0d-28eb58cd4361/xovebolava.pdf
    • https://uploads.strikinglycdn.com/files/236ce1b9-1924-46b6-9ba3-ed3cc016344f/start_your_own_blogging_business.pdf
    • https://s3.amazonaws.com/ropuba/15567994812.pdf
    • https://uploads.strikinglycdn.com/files/a49b7050-3537-48cc-ad87-ad2dd4db7f51/26619076858.pdf
    • https://uploads.strikinglycdn.com/files/3d333de3-bd77-406f-a5ea-d6e0ef4bd1c2/the_five_dysfunctions_of_a_team_team_assessment_2nd_edition.pdf
    • https://s3.amazonaws.com/lorifawuvawot/98274044265.pdf
    • https://s3.amazonaws.com/likerajatob/assurance_of_support_release_form.pdf
    • https://s3.amazonaws.com/bepukuba/vadakusa.pdf
    • https://uploads.strikinglycdn.com/files/135b167f-9489-40c9-932f-fb5b1ac47d30/zunufevififumeputamuwug.pdf
    • https://s3.amazonaws.com/daxemo/xezagemev.pdf
    • https://s3.amazonaws.com/lurutopobi/kisulakugi.pdf
    • https://uploads.strikinglycdn.com/files/5bbbf6c0-ed2b-4415-a684-919ca15d266b/24059501137.pdf
    • https://s3.amazonaws.com/sorogamat/treating_chloroform_in_well_water.pdf
    • https://s3.amazonaws.com/solonebosop/steam_api64._dll_missing_gta_v.pdf
    • https://s3.amazonaws.com/popilo/oops_concepts_in_java_code_project.pdf
    • https://s3.amazonaws.com/wixatax/friedrich_nietzsche_books_in_spanish.pdf
    • https://s3.amazonaws.com/womirofop/51905784403.pdf
    • https://s3.amazonaws.com/loneminovu/surubuparuwukox.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebe7.bin
1ef8da4b0b9130e6d0326f47270eded171ab6971193ce888623a84ed7d097720
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBE7 5388 bytes
font_01_sfnt_off0000fe27.bin
ee7678323e0a239f899618d192b451d50342971bf4a7bf47d8abad72237ea42f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE27 10644 bytes
font_02_sfnt_off000122e5.bin
a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x122E5 16204 bytes