Malicious PDF — malware analysis report

Static analysis result for SHA-256 e117ccbcce28362f…

MALICIOUS

PDF

80.3 KB Created: 2021-04-29 02:10:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ad239314a165bb92c8746d48d1e855e6 SHA-1: b7ef33986bada3078a0954725c504e160fcd17d8 SHA-256: e117ccbcce28362f94278919c26fe8506863fdc24bcc1810fc59a801ede3f765
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious. It contains an embedded URI pointing to 'vilenefex.ru', which is likely a phishing or malware distribution site. The document body, though heavily obfuscated, appears to contain product-related text, suggesting a lure to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=weber+spirit+e-210+lp+gas+grill+black
    • https://natitapa.weebly.com/uploads/1/3/1/3/131379406/779368.pdf
    • https://najibiwamedixi.weebly.com/uploads/1/3/4/9/134901652/laloj.pdf
    • http://ital-girl.space/41511654552nzo52.pdf
    • http://boforobevuziko.mywebcommunity.org/adjektivdeklination_nullartikel_bungen.pdf
    • https://faluwesidiji.weebly.com/uploads/1/3/0/7/130738597/474943.pdf
    • http://sexedate69.site/christmas_cake_decorated_with_candy_caneseqasg.pdf
    • http://digitaltoolsfor.xyz/how_much_can_a_personal_trainer_earn_in_canadaub7ew.pdf
    • http://bella24.xyz/can_the_ti-84_plus_ce_be_used_on_the_actvyh21.pdf
    • http://pidusejop.medianewsonline.com/simile_worksheets_grade_5.pdf
    • http://pochta-24.cc/lowrance_elite_3x_dsi_installationpdxcn.pdf
    • https://radutarogo.weebly.com/uploads/1/3/4/3/134379411/8489513.pdf
    • https://wetusaseri.weebly.com/uploads/1/3/5/2/135297966/4060348.pdf
    • http://logoped-samara.ru/bidezobuu8ocz.pdf
    • http://reduslimitalia.website/laxuwebiwuq7vnq.pdf
    • https://noriledefokotox.weebly.com/uploads/1/3/0/7/130739853/xomob.pdf
    • https://rijejoxutozi.weebly.com/uploads/1/3/4/5/134599637/vesefezebolopis_megekisupoxene_vukivesezazod_kotorop.pdf
    • https://juzowugaf.weebly.com/uploads/1/3/4/7/134773334/ributoxedud-dexov-duxoxib.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/xunilukegez/jazoworopakoj.pdf
    • http://zedowep.atwebpages.com/vajusurigutoxuwewujeji.pdf
    • https://s3.amazonaws.com/zalisujezajaje/61624039493.pdf
    • https://s3.amazonaws.com/luxelula/netflix_android_stop_autoplay.pdf
    • https://s3.amazonaws.com/figidireki/68134728338.pdf
    • http://jimomurapujivo.onlinewebshop.net/75430271398.pdf
    • http://nizowozutagele.atwebpages.com/pdf_bookmark_editor_online.pdf
    • https://s3.amazonaws.com/kiremefegonar/fundamentals_of_digital_logic_with_vhdl_design_by_stephen_brown.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8af.bin
1dbb3c5d5ecb5c787b7238f2f629649e1911869e3a7e47f5266e52f8f3a38f7e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8AF 5676 bytes
font_01_sfnt_off00010c33.bin
f055ef66d4ba6ac2c348b254354bfee4804e5b39d929fcf5f1f0bb24a35685ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C33 11548 bytes