Malicious PDF — malware analysis report

Static analysis result for SHA-256 e258897f33b6fcad…

MALICIOUS

PDF

94.5 KB Created: 2021-03-15 16:41:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e67d83a9fc67a9867ffe8151d63db6f0 SHA-1: 1d123ec3d96954af215e63a4ce780faf7c6ab21e SHA-256: e258897f33b6fcad281754e86184c618b41bb3e61f5db8223c62ffcefdc61146
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into downloading further malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. The document body, though heavily obfuscated, contains strings related to game downloads, suggesting a lure for phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/aws?utm_term=baldur%2527s+gate+2+dark+alliance+ps2+iso
    • https://cdn.sqhk.co/tifozeborot/hb7hjFe/fashion_design_books_for_beginners_free.pdf
    • https://static.s123-cdn-static.com/uploads/4388280/normal_5fec54b89d6c3.pdf
    • http://axecheat5.xyz/baffle_wall_between_transformersvtf93.pdf
    • http://reduslim-italiaoficial.site/file_accident_report_online_floridao74xy.pdf
    • https://static.s123-cdn-static.com/uploads/4388608/normal_6005a7f8ef9a8.pdf
    • http://vibolofisef.mywebcommunity.org/mewavif.pdf
    • http://idealica-columbia.site/zemikanuxaflocfm.pdf
    • http://rekugegik.scienceontheweb.net/interventions_in_mental_health_disorders.pdf
    • http://mikazuxo.mypressonline.com/gupiwalosawujololif.pdf
    • http://pigigozoruda.mypressonline.com/is_saitama_a_parody_character.pdf
    • http://pressit.fun/740324245354koh5.pdf
    • http://italiahot.fun/league_of_berserk_mod_apk_2019p3e39.pdf
    • http://ig-copyrightnoticehelp.com/2017_ktm_350_exc_f_owners_manualour3t.pdf
    • https://cdn-cms.f-static.net/uploads/4471464/normal_60399f218c270.pdf
    • https://cdn.sqhk.co/jifibipex/bsjgRUS/game_dev_tycoon_cheat_table.pdf
    • https://cdn.sqhk.co/jatobeguji/gM4idgi/67678571688.pdf
    • https://cdn-cms.f-static.net/uploads/4409238/normal_5fe75d4e747d6.pdf
    • http://raifaisentgo.online/kenmore_water_softener_troubleshootingwgia8.pdf
    • http://rowexusaje.mypressonline.com/fabevuniranukizojo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://85d2c5a2-fc31-4f76-86b4-4ebe2abe2bf4.filesusr.com/ugd/a8cc01_3deecff0f3644bc6a510e4af67764b3d.pdf?index=true
    • https://3b044092-e341-4c69-a8e2-52b14fc1865f.filesusr.com/ugd/370021_f060ed347ed44a5c94cc007ea9ec1004.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001349d.bin
d91d8857ecade069a5451fab0afee4cd57c9b06a239845cbd9163d960054016e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1349D 5520 bytes
font_01_sfnt_off0001477f.bin
5778f1bfc7fbe6bb359d7fd2428b1d00cabe77b21adf82c34a1a4d608d667854
pdf-font-stream PDF embedded font (sfnt) at offset 0x1477F 10900 bytes