Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1731e53f52499b5…

MALICIOUS

PDF

79.0 KB Created: 2021-05-29 11:45:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: 55eeb4a441fad6aefbb89e6933955e5c SHA-1: 4a3be9224b2f6b9af2230e67b87b6fafd23680dd SHA-256: e1731e53f52499b5964379c310f9e8cb88444f4f124fbf39c44d792792cbcf1f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that directs users to a domain associated with phishing. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or credential harvesting. Although no scripts were extracted, the presence of a suspicious URL and the document's deceptive content suggest an attempt to trick the user into clicking the link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/123?utm_term=understanding+equifax+credit+report+codes PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4483072/normal_601751d7bfb22.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417405/normal_605eefe793a3b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4459177/normal_604ac769bc621.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4467950/normal_601410ff84d4b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417037/normal_6017361c645a0.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4503584/normal_60b1eb17e03e0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366407/normal_6061ab68b9a57.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/3b64af28-433f-4419-ab50-fa21a34f765d/dikebufuraw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/54409d57-720a-401a-8a1f-1184db7ee43c/nobojevivilaresux.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/07026656-87b1-443c-8de2-2d5d8e37f54c/32886834679.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4938a043-fc86-45c8-8fd1-5d90b3643375/why_does_my_heater_keep_saying_e1.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a8950849-3341-40a9-8421-10e687bcd30f/what_are_the_properties_of_simple_molecular_substances.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa7dfce9-c4df-4458-8f1a-b1d64a34eb48/how_to_study_for_ca_real_estate_broker_exam.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eafcd6df-db89-44bc-95e0-3aded82ab9d3/graco_pack_n_play_sheets_2_pack.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/efb155e9-ee4c-4a0c-8265-0a72c0311125/73045892962.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d0cd1790-7ce7-463f-a392-7072bfc5207c/dd_beyond_coupon_jan_2021.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3d6185f9-4929-496f-ad32-b516dbe11bca/can_you_cook_chicken_in_air_fryer_without_oil.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2b4803da-4e60-4f10-b2db-80fc86933a68/rimidowuken.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e5496aef-ab28-481d-ab9b-4271e288936e/48916787895.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b3511528-f514-4f2c-9f19-b0c4cdfb7a96/how_do_you_reprogram_a_liftmaster_keypad.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b0c1c92c-3e85-4627-bd2c-0da17b04415e/82733185439.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5f7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF5F7 5476 bytes
SHA-256: 35e81326ec902dba570e27695a532b938a94a0b0e7f3f3bf4d4b304e67b955cb
font_01_sfnt_off000108af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x108AF 10900 bytes
SHA-256: 03a9278e8fcc5b81ae8030a27bfeaf0bdc424fa1794596cd8e1080b41a0667aa