Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2cb44c9b7654e3e…

MALICIOUS

PDF

91.4 KB Created: 2021-03-25 11:44:04 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ecc4651dbe0300cb2460cdba08b11c25 SHA-1: 8ecee9272718ecd33d9de9b35e59d5a4ac5d8ee3 SHA-256: e2cb44c9b7654e3e177db406637d8e7391f870df2772e1bfed9995fd26c73fe3
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is identified as malicious by a machine learning classifier and ClamAV, with heuristics indicating it uses an advance-fee scam lure. The document body, though heavily obfuscated, contains keywords related to prizes and delivery, consistent with this scam type. An external URI pointing to 'zajinet.ru' was extracted, likely part of the phishing infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/award?keyword=purpose+driven+life+journal+pdf+free
    • http://geekcods.com/pumenalobanenebukoxyn5fc.pdf
    • http://mozaduz.mygamesonline.org/lewefitetapupizupejux.pdf
    • http://fredo.run/88107512125fwga0.pdf
    • http://betogav.22web.org/ap_language_vocabulary_quiz.pdf
    • http://rekopeza.22web.org/los_atributos_de_dios_segun_la_biblia.pdf
    • http://vezadawebowa.iblogger.org/workbook_sheet_reference_vba.pdf
    • http://prostosite.site/woods_timer_50015_manual7gr9m.pdf
    • http://kemedejovon.getenjoyment.net/cahier_des_charges_garderie_scolaire_tunisie.pdf
    • http://budokudepa.scienceontheweb.net/what_are_some_interesting_facts_about_ancient_greece.pdf
    • http://linavaluviriv.getenjoyment.net/future_perfect_continuous_tense_worksheet.pdf
    • http://bejisosubonito.sportsontheweb.net/norizumuvinit.pdf
    • http://tazedipimazuri.22web.org/wrist_strain_exercises.pdf
    • http://ericksandoval.com/is_panda_express_healthy_during_pregnancy6xac0.pdf
    • http://detonic-italy.website/smim_enderal_fix_download03yoo.pdf
    • http://lifegirls.site/xelozeronuvenujowovis0cc46.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/896f87fb-b051-41aa-9625-91e95c113b6f/roku_streaming_stick_3810x-bdl1.pdf
    • https://s3.amazonaws.com/boxujetanonikuv/how_to_fix_e1_error_on_haier_washing_machine.pdf
    • https://s3.amazonaws.com/kakekojezutok/why_cant_you_have_surgery_if_you_have_high_blood_pressure.pdf
    • https://uploads.strikinglycdn.com/files/d2b46c8c-03e3-427c-ae2d-c440e6704582/25874711800.pdf
    • https://uploads.strikinglycdn.com/files/c87af982-e2ba-4274-8621-f1204d13a190/madonna_sex_book.pdf
    • https://uploads.strikinglycdn.com/files/52104d49-e88b-4c74-8ff3-adfb5531d69e/29190833086.pdf
    • http://borovob.epizy.com/60137454652.pdf
    • https://uploads.strikinglycdn.com/files/7d72c8db-c373-42ef-95ba-a263698c7da7/loketif.pdf
    • https://s3.amazonaws.com/jotizifime/69625336061.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000126b6.bin
d8e9640d862e23f0174b4c5934f609596ac7012b30a4f8578202de742ef1f4c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x126B6 5172 bytes
font_01_sfnt_off00013866.bin
979a40a332e10cc9f37bed99c98710b911e00cb5d99c1e3e183d010221edec33
pdf-font-stream PDF embedded font (sfnt) at offset 0x13866 11876 bytes