Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0ce6f20137d145e…

MALICIOUS

PDF

92.6 KB Created: 2021-04-08 09:24:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 676d0734cf6a37b43d6f530e282086ad SHA-1: 96c4e447b327d1b8d0074680cdc87af4dacbd7d3 SHA-256: e0ce6f20137d145e1824db504d03ab867a4f6ae31174658d497fb4b6a17f25e5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a malicious domain. The document body, though heavily obfuscated, includes text related to 'Gossip girl season 6 episode 2', suggesting a lure to entice users to click the malicious link. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=gossip+girl+season+6+episode+2
    • https://cdn-cms.f-static.net/uploads/4375341/normal_605d6d2298f69.pdf
    • https://cdn.sqhk.co/bexutavukaro/hhhbyhi/descargar_aplicacion_cuballama.pdf
    • https://static.s123-cdn-static.com/uploads/4446773/normal_5fc67a38e1284.pdf
    • https://cdn.sqhk.co/rudugebakivo/t0hidc8/best_movie_streaming_apps_for_android_2020.pdf
    • https://cdn.sqhk.co/melipetoluf/5lidvgj/snake_and_ladder_game.pdf
    • https://cdn.sqhk.co/juzurupivepo/ihF6Sco/paxabixofisinetorowedorad.pdf
    • https://cdn-cms.f-static.net/uploads/4382407/normal_605d8e1170b94.pdf
    • https://cdn-cms.f-static.net/uploads/4487005/normal_6027ef23d491a.pdf
    • https://cdn.sqhk.co/naludibeg/bKgfhjm/18794795971.pdf
    • https://cdn-cms.f-static.net/uploads/4457876/normal_605150fc17ecf.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2a8112c6-8970-4990-be76-c0c5b4f2bb56/sunobijofogiluvitexej.pdf
    • https://uploads.strikinglycdn.com/files/0dd79bc4-e5a5-4aff-a836-826210875911/nodozimijizologi.pdf
    • https://s3.amazonaws.com/bolovopizonuki/13780804139.pdf
    • https://uploads.strikinglycdn.com/files/3e80dc66-85bf-49f0-b97c-dac4a73fa42d/padi_open_water_diver_certification_expire.pdf
    • https://s3.amazonaws.com/gowupuzokowuxes/bwin_app_for_android.pdf
    • https://uploads.strikinglycdn.com/files/a78c1944-bd15-470a-8338-04df8bd82fa4/why_is_my_verizon_router_flashing_red.pdf
    • https://uploads.strikinglycdn.com/files/232560c0-1461-46ac-9d1c-4c3e56fba7d6/line_6_hx_stomp_vs_boss_gt_1000_core.pdf
    • https://uploads.strikinglycdn.com/files/97110019-5dd5-4271-8623-b926fff9fb19/how_do_i_get_ndt_certified.pdf
    • https://uploads.strikinglycdn.com/files/0a799954-c9eb-4119-9cb3-9564e3a78770/gogisugurisa.pdf
    • https://uploads.strikinglycdn.com/files/ceeb55c4-0929-44ae-a3a1-488b8dccacbf/top_books_on_chakras.pdf
    • https://s3.amazonaws.com/nademopor/bradenton_weather_report.pdf
    • https://uploads.strikinglycdn.com/files/93875dc6-9405-4abe-9ff2-8f1b34f7eba7/tezimix.pdf
    • https://uploads.strikinglycdn.com/files/f5efc3f0-0fdf-4d7c-b2bb-0134d444217a/jensen_cd_560_reviews.pdf
    • https://uploads.strikinglycdn.com/files/a1ab4211-0ff6-4079-81df-8395e478332c/kenabowatubeva.pdf
    • https://uploads.strikinglycdn.com/files/0c0b665f-6834-4366-af07-808d6fecbeed/zexevokot.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012aa9.bin
94fcb1850fbe895289172da857a8650e13b21898dad5d31c7f556d3145a10bfa
pdf-font-stream PDF embedded font (sfnt) at offset 0x12AA9 5444 bytes
font_01_sfnt_off00013d3a.bin
8284f0d005f85027db89e42c77268b958eb02fbe22c37d911bf1f13213c3f974
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D3A 11324 bytes