Malicious PDF — malware analysis report

Static analysis result for SHA-256 e33aaf835ae9a36b…

MALICIOUS

PDF

86.1 KB Created: 2021-02-21 06:03:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: d5064f2699c3b149f5e49adc4466860c SHA-1: a0a4dcecea995d72875e6c2dc6c64febf4f07cae SHA-256: e33aaf835ae9a36bbadf5a6292bcd7058252c526c882db3f3447223af764dbfa
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a specific ClamAV detection name indicating it's a phishing trojan. An external URI pointing to 'maypoin.ru' was extracted, which is highly suspicious. Although no scripts were explicitly extracted, the PDF structure and the presence of external URLs suggest an attempt to redirect the user to a malicious site, likely for phishing or to download a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/123?utm_term=saga+of+tanya+the+evil+novel+8 PDF link annotation
    • https://cdn.sqhk.co/melipetoluf/fxJjgIq/felopafopalesixefanuwewe.pdfIn PDF document text
    • https://cdn.sqhk.co/dufubimaru/g7W6Cjh/america_s_funniest_home_videos_previous_host.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/dalava/java_string_format_javadoc.pdfIn PDF document text
    • http://fuxufotab.epizy.com/gakugesizujatisetewe.pdfIn PDF document text
    • https://s3.amazonaws.com/jipowumat/nojuwo.pdfIn PDF document text
    • https://s3.amazonaws.com/wunupalezozerud/non-_binding_letter_of_intent_template.pdfIn PDF document text
    • https://s3.amazonaws.com/bolovopizonuki/types_of_sentences_worksheets_with_answer_key.pdfIn PDF document text
    • http://bumemelowogo.rf.gd/53748704595.pdfIn PDF document text
    • https://s3.amazonaws.com/kefiperizonofu/maps_for_minecraft_pe_free_ios.pdfIn PDF document text
    • http://vefejabenu.rf.gd/6136444153.pdfIn PDF document text
    • https://s3.amazonaws.com/rutufokedizon/buwopojiper.pdfIn PDF document text
    • https://s3.amazonaws.com/zarevizebi/87706137879.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d462.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD462 20188 bytes
SHA-256: 0216b8b829ba0ee199f520da35cc5a515a3e3a0e2d3859f8f06e5229cbef6f0c
font_01_sfnt_off000114db.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x114DB 5216 bytes
SHA-256: 0a3b8fe15a6b69bc1a1b6c4523afd95134641dc735911db68d09573a0f9131cd
font_02_sfnt_off000126b0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x126B0 10500 bytes
SHA-256: c3888d074b5a1a51901616bbb6212a998c4e327fbd5a8c9999c24042760df6f3