Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1561576ed270f0b…

MALICIOUS

PDF

156.8 KB Created: 2021-03-18 21:55:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 1e7784c696c345ff9bfa46a64a70c24a SHA-1: 370503f67d9d8dcbb260b3e184d98cb5f3b5a93d SHA-256: e1561576ed270f0bf0261f4aeca37f18391e6280732fb7b7ffe4a8aa37f09501
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/award?keyword=the+bacchae+pdf+with+line+numbers PDF link annotation
    • https://jinuvavuvebox.weebly.com/uploads/1/3/4/6/134612635/wadanita.pdfIn PDF document text
    • https://betutoza.weebly.com/uploads/1/3/4/8/134899773/61514a802d133c9.pdfIn PDF document text
    • https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/9f5378.pdfIn PDF document text
    • https://tirusagoxavux.weebly.com/uploads/1/3/5/3/135329940/vogugosuzupuk.pdfIn PDF document text
    • https://zomerasojukoluw.weebly.com/uploads/1/3/4/7/134769652/82cf4d9d98.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/f95cdb87-0e8f-4feb-b5a4-f8f7611c81fe/15496428447.pdfIn PDF document text
    • https://s3.amazonaws.com/fifuto/batman_dark_knight_in_telugu.pdfIn PDF document text
    • https://9d1e48ad-bcd7-4831-9b7b-7108443a63b6.filesusr.com/ugd/136d07_d49c689256d9468f89aa06a41951a135.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/vidadaviwal/lagu_cinta_laura_vida.pdfIn PDF document text
    • https://s3.amazonaws.com/lanubili/takavukosugavugota.pdfIn PDF document text
    • https://s3.amazonaws.com/kujesulad/free_photo_calendar_template_2020.pdfIn PDF document text
    • http://novoniranalisa.epizy.com/jaroxudigiduzufo.pdfIn PDF document text
    • https://3f46bf15-0a8c-4e80-b3e5-a2e3bf90e008.filesusr.com/ugd/8e6e76_f3cc007c80e948e5903f661c49f7c463.pdf?index=trueIn PDF document text
    • http://bikaduwixunu.epizy.com/what_are_positive_behavioral_interventions_and_supports.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8eef2e89-e5fe-46d5-90d7-a0bcbfa6d9d1/xikuziledijisinirux.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1b2aba38-72a4-462c-993f-5a0b80e8c44e/sajafagizirima.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7d869a0a-ea24-4a70-b806-9750c4758b23/internal_check_in_auditing_definition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4658ab9-6c39-4b63-bb72-c374f8ed699a/can_i_charge_my_garmin_while_running.pdfIn PDF document text
    • https://ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com/ugd/eda9ba_70ada05726684b26bf7584a8aa046af2.pdf?index=trueIn PDF document text
    • https://4dd4a32c-aced-41d2-87e6-7ff9ca8080d7.filesusr.com/ugd/6d6f33_3173e4a2a24746fc919156cc5e9d4f32.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00022d74.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22D74 5576 bytes
SHA-256: 122091842e516bdbe350f8fb01605a6f0b8b10a0e625086a9a3069f4425f38f4
font_01_sfnt_off0002404a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2404A 10676 bytes
SHA-256: bd1f57f102318d7826429d65be2551667b8ffa8a82a6b94c88860484d0ae9a62