Malicious PDF — malware analysis report

Static analysis result for SHA-256 df7546de85d9bfb6…

MALICIOUS

PDF

72.5 KB Created: 2021-03-03 00:06:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 57de5bac5fa14830ff01b20a52b4d5b3 SHA-1: c2086817eb306d0f48bf8fdbd5286ac5467dddb7 SHA-256: df7546de85d9bfb6d80b43aff5256dc2b2b10f486a3c21b2c7cc1e73e5a616e9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to 'crophysi.ru', which is likely used to host a malicious payload or phishing page. The document body contains garbled text, suggesting it is not intended for direct user consumption but rather to exploit vulnerabilities or deliver further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/wix?keyword=bear+grylls+pants+south+africa
    • https://katudiwuf.weebly.com/uploads/1/3/6/0/136006549/a6ef6.pdf
    • https://roxuvipiga.weebly.com/uploads/1/3/4/6/134637137/gisiralu.pdf
    • https://supavutoni.weebly.com/uploads/1/3/4/7/134713891/7582317.pdf
    • https://xivapumi.weebly.com/uploads/1/3/1/6/131606059/e790cf.pdf
    • http://kedepoba.sportsontheweb.net/steps_to_personal_revival_sda.pdf
    • https://wafulezejo.weebly.com/uploads/1/3/4/7/134748518/023c87a2d1.pdf
    • http://bikejesoxatelo.mygamesonline.org/wd_my_cloud_ex2_firmware_update.pdf
    • https://xekuruwagimutuz.weebly.com/uploads/1/3/2/6/132696141/3947595.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/watajive/jogow.pdf
    • http://luvojidepezepag.epizy.com/fisher_price_infant_to_toddler_rocker_dark_safari_recall.pdf
    • https://s3.amazonaws.com/fizufapu/sundered_skies_character_sheet.pdf
    • http://mewexudidis.epizy.com/vcruntime140._dll_rpcs3.pdf
    • http://xogamix.rf.gd/what_is_the_towing_capacity_of_a_2012_jeep_grand_cherokee.pdf
    • https://s3.amazonaws.com/debiwelof/jazabusafugununokosojumog.pdf
    • https://s3.amazonaws.com/woxewiwupir/77445497386.pdf
    • https://s3.amazonaws.com/zakunafu/67265786805.pdf
    • https://s3.amazonaws.com/nefagolom/vehicle_information_api_india.pdf
    • https://s3.amazonaws.com/fotojipifuzitul/duxatesew.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d15e.bin
f7c72d9bf251d1b927df1905bfd9c8299a60f01d9620854868585ebe4f86c93c
pdf-font-stream PDF embedded font (sfnt) at offset 0xD15E 5308 bytes
font_01_sfnt_off0000e371.bin
41a7a450e66e3147251e6f1684bd0cf619863d7404dbe13733da704a5e4e0455
pdf-font-stream PDF embedded font (sfnt) at offset 0xE371 10284 bytes
font_02_sfnt_off000106b2.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x106B2 4324 bytes