Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1a8149c4bfcf836…

MALICIOUS

PDF

182.4 KB Created: 2021-03-22 16:59:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bbffeb8d482dc339349ee492a83c8b3d SHA-1: addbe23bc74b54a7651b28416f6ae30da451ae42 SHA-256: e1a8149c4bfcf8368b9b406c36914b61e27414793fc969b18165e37cfa47d733
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an external URI pointing to 'vilenefex.ru', which is likely part of the lure to download a payload. The document body, though truncated and obfuscated, suggests a theme of free website templates, aligning with a phishing pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=free+website+templates+for+photography+business
    • https://cdn.sqhk.co/bogovureg/ficfxgd/nowikeririvupe.pdf
    • https://cdn.sqhk.co/kavejufa/rjjhige/mlb_news_and_rumors_red_sox.pdf
    • http://durowan.sportsontheweb.net/6224086760.pdf
    • https://cdn.sqhk.co/kifukuvitog/Voiidgg/hide_and_seek_korean_movie_netflix.pdf
    • https://cdn.sqhk.co/paxelababeg/cNjheji/51385303013.pdf
    • https://static.s123-cdn-static.com/uploads/4409616/normal_6000ed8285b56.pdf
    • https://cdn-cms.f-static.net/uploads/4485434/normal_60511c27d36e8.pdf
    • http://bekunogoxabune.iblogger.org/326516827.pdf
    • https://cdn-cms.f-static.net/uploads/4471275/normal_601ef196eaf0c.pdf
    • https://static.s123-cdn-static.com/uploads/4417423/normal_5ff3d70ce3527.pdf
    • http://kajejib.medianewsonline.com/zubiwagaredi.pdf
    • https://cdn-cms.f-static.net/uploads/4457620/normal_5feaec89d73b5.pdf
    • http://kudonolenukiv.22web.org/how_do_i_connect_my_canon_pixma_mg2520_printer_to_wifi.pdf
    • http://tixobikoxemegor.22web.org/55657086809.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://254a6a59-343e-4b7e-907c-c4819e171fff.filesusr.com/ugd/decf6f_06558450117a46ad9b4d10951f42e983.pdf?index=true
    • https://f59c0a4d-c104-43ac-8966-a5978cdf1b8c.filesusr.com/ugd/0c1ebd_1c1f9fb691c04bc6a05b9ec3ec2d94fb.pdf?index=true
    • https://0306adf0-382e-42f1-903d-71c3961c97f1.filesusr.com/ugd/7ff653_bf44f3d172d4492983eed7a9f290b542.pdf?index=true
    • http://zepibugab.rf.gd/3942890418.pdf
    • http://palezonipegodaf.epizy.com/79506055611.pdf
    • https://uploads.strikinglycdn.com/files/dfd99a34-7adf-403d-b741-62618a3c012f/84334258195.pdf
    • https://uploads.strikinglycdn.com/files/11eb7dec-acc4-44b8-b995-90cba22c8884/are_romeo_y_julieta_cigars_good.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00029122.bin
618cc86c7f32c57dde520a26c5579d4cf88457c33a1742aa6c7f5d91aac32785
pdf-font-stream PDF embedded font (sfnt) at offset 0x29122 5604 bytes
font_01_sfnt_off0002a41d.bin
3d6f535bc368d639d0f4b89a8e2e6cb0af140569d70e2bae774be9489481d539
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A41D 11540 bytes