Malicious PDF — malware analysis report

Static analysis result for SHA-256 d970f7711f7bd5a0…

MALICIOUS

PDF

80.1 KB Created: 2021-05-18 04:41:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 339f23070ceae8ec1324770506a1e254 SHA-1: 96617a3740f4e8b1fb5c0663c0c0f0a6561ffa3e SHA-256: d970f7711f7bd5a044cf70db10fe7ce5b48aa271dcd4e085094644afbc8b5599
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for an external URI, pointing to a suspicious domain. The ML classifier and ClamAV detection strongly indicate maliciousness. The embedded URL is likely intended to redirect the user to a phishing or malware distribution site, disguised as a worksheet answer key.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=area+of+composite+figures+worksheet+6th+grade+answers
    • http://vigemej.iblogger.org/11576114473.pdf
    • http://gubokiwurajot.iblogger.org/mowesufoboges.pdf
    • http://xonibiz.22web.org/mandated_reporter_nysed.pdf
    • http://vuvubul.iblogger.org/25009418888.pdf
    • http://novedexezenel.66ghz.com/87492392936.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xesigeze/private_practice_cast_season_3_episode_6.pdf
    • http://rujipezoj.epizy.com/breakthrough_prayer_jim_cymbala.pdf
    • http://wonenuw.epizy.com/tebaxen.pdf
    • https://s3.amazonaws.com/rakabexozu/kathai_tamil_movie_song.pdf
    • https://uploads.strikinglycdn.com/files/3bc003e8-51bf-4ab4-bf9a-4bb4474f5a6b/borikugogidegegelawura.pdf
    • https://s3.amazonaws.com/xeponodij/how_to_say_jesus_prayer_in_greek.pdf
    • https://s3.amazonaws.com/kalanejaxutilif/gracie_barra_jiu_jitsu_curriculum.pdf
    • http://ninalosuza.rf.gd/26326954730.pdf
    • https://uploads.strikinglycdn.com/files/30f0074d-c4d9-4b7c-9319-092cc920303e/are_permit_test_multiple_choice.pdf
    • https://uploads.strikinglycdn.com/files/097a5a9f-ad2f-46d3-b866-01285b70495e/ham_without_oven_bagel.pdf
    • http://gefosudevepap.rf.gd/93251597301.pdf
    • http://dimonejoxu.rf.gd/frp_bypass_app_for_android.pdf
    • http://vezuxafafifobo.epizy.com/is_aircraft_maintenance_in_demand.pdf
    • https://uploads.strikinglycdn.com/files/541afd5b-3468-41ae-b261-f984709a265a/kaplan_mcat_practice_test.pdf
    • https://s3.amazonaws.com/bugutaj/begatajimegilenevejimuze.pdf
    • https://uploads.strikinglycdn.com/files/e060fedf-9788-4f4d-9664-b50d2afb5d9e/how_much_does_sweat_bbg_cost.pdf
    • https://uploads.strikinglycdn.com/files/65d3b875-93b7-418c-bfec-59e4602038d4/how_do_i_connect_my_bluetooth_keyboard_and_mouse_to_my_mac.pdf
    • https://uploads.strikinglycdn.com/files/e04a3686-de43-4593-a2ff-6e2291b04790/nosler_load_data_6.5_creedmoor.pdf
    • http://dexifuv.epizy.com/bissell_powerforce_compact_turbo_bagless_vacuum_cleaner_2690.pdf
    • https://uploads.strikinglycdn.com/files/7a47eb35-6898-4646-9b5a-27586beb8162/do_steam_dryers_hook_up_to_cold_or_hot_water.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f88e.bin
b99a0faf954bebef9187c99cf6f8df2d4984dfece1f2fbf0c1afe1737be75e32
pdf-font-stream PDF embedded font (sfnt) at offset 0xF88E 5836 bytes
font_01_sfnt_off00010c5a.bin
81709812874d17a757d8e99df4215aeec3a07d1470e8db046a3e13cf84e970ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C5A 11164 bytes