Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0cb60c99c00a3ef…

MALICIOUS

PDF

74.8 KB Created: 2021-03-22 09:50:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 91d8eed760ee3e3f3ec46e70f3341ee0 SHA-1: e33ef2c83a29a763211d749a461c13edd8e519f8 SHA-256: e0cb60c99c00a3ef16900808abf1500c13d8b9bd850d1212f26a80cfb0701b10
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The sample was identified as malicious by a machine learning classifier and ClamAV, with high confidence. Heuristics indicate it uses an advance-fee scam lure, presenting language related to lotteries or prizes combined with parcel delivery requirements. An external URI was found pointing to a URL that appears to be part of this scam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/award?keyword=java+basic+programs+examples+pdf+free+download
    • https://cdn.sqhk.co/zobelekivix/TmiehdQ/titan_quest_switch_update.pdf
    • https://cdn.sqhk.co/kufejeni/9ZbhbZf/oklahoma_state_football_roster_2013.pdf
    • https://cdn.sqhk.co/kominepoli/bjjgeib/bow_weapons_destiny_2_without_forsaken.pdf
    • https://cdn.sqhk.co/gulaxemetila/gtFieiF/tunebebinoxejobarozu.pdf
    • https://cdn.sqhk.co/lutotilivik/Ehjjghb/42090274208.pdf
    • https://cdn.sqhk.co/wuvukidovime/zsIggid/rotuloler.pdf
    • https://cdn.sqhk.co/guviterolovu/XsdviaO/lewazuzawutulub.pdf
    • https://cdn.sqhk.co/tawibonikigo/heBjehb/revolutionary_iran_michael_axworthy.pdf
    • http://xinuvaro.sportsontheweb.net/synonyms_and_antonyms_with_bangla_meaning.pdf
    • https://cdn.sqhk.co/libuzewis/cigiegd/flying_ants_in_house_after_rain.pdf
    • http://java67.comIf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f0256821-dc29-4e1b-a1de-2cd00b2a8c04/wuvijinadimu.pdf
    • https://s3.amazonaws.com/tofizo/vegas_pro_crack_version.pdf
    • https://s3.amazonaws.com/babetafaperaxov/how_to_get_osha_forklift_certification.pdf
    • https://uploads.strikinglycdn.com/files/0dc4fb7b-e3e9-49d0-98d9-4212c5e34f69/37043472871.pdf
    • http://bebojivim.myartsonline.com/binocular_vision_disorder.pdf
    • https://s3.amazonaws.com/niwotipugonuvoz/adda_movie_lo_songs.pdf
    • https://uploads.strikinglycdn.com/files/53cbfd91-4df6-4cf5-b64f-fd1f4a98af35/zagidapegezefugilavifek.pdf
    • https://s3.amazonaws.com/jenagubadopi/crystal_maiden_item_build_guide_dota_2.pdf
    • https://s3.amazonaws.com/fopalew/dunixewajabog.pdf
    • http://lamupimifuban.onlinewebshop.net/data_science_and_big_data_analytics_wiley.pdf
    • http://javarevisited.blogspot.com
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e54e.bin
59748576cebcd2c52970b54571a43ba2b223ac1430c8735d4b44ebbbc7e3f1d5
pdf-font-stream PDF embedded font (sfnt) at offset 0xE54E 5824 bytes
font_01_sfnt_off0000f922.bin
8d773b5d75b95714e0a4f695f1e2a90bdbea710ba66ba6efd239e28114f7230f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF922 10648 bytes