Malicious PDF — malware analysis report

Static analysis result for SHA-256 e525adccc05f0e19…

MALICIOUS

PDF

105.1 KB Created: 2021-04-09 12:50:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-02
MD5: 1836cb67e058738037eb725412e0a0f8 SHA-1: 200dddcc204860c2abb3616395861f7e0c501f5b SHA-256: e525adccc05f0e19fc541df53fed5e1ac64a536a9ea0e56b1575d12ed253deaa
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains heuristics indicating external URI usage and is flagged by a machine learning classifier and ClamAV as malicious. The document body, though heavily obfuscated, appears to be a lure related to a book summary. The embedded URL `https://pelibifir.ru/strik?utm_term=resumen+del+libro+tus+zonas+erroneas+por+capitulos` is the most prominent IOC, suggesting a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=resumen+del+libro+tus+zonas+erroneas+por+capitulos PDF link annotation
    • http://sberhome.ru/413000879193s2on.pdfIn PDF document text
    • http://jumbochecker.com/what_is_a_crp-hs_blood_testks2yg.pdfIn PDF document text
    • http://kfnwejfnkwheklf.space/uk_visit_visa_application_form_from_usabkmax.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413862/normal_6048c14e2e79d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420599/normal_601749890dc5c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4402944/normal_5fe454586c1f5.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4427783/normal_5fccbbf71440f.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4459027/normal_5fe22d03c915e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4369505/normal_5fe0f2961d31a.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408471/normal_603f551e93242.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4489730/normal_604d13ce59f2c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/e455e175-078c-488b-8df8-ae038892151b/motorola_bluetooth_headset_setup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5b99f0e7-4449-4ab2-962a-59334930ed1b/vokodemokalutom.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2571a1ec-a921-4e53-9957-bffcefc5c798/how_much_weight_can_a_2017_nissan_pathfinder_tow.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/359a1147-4b93-47d6-9c1e-882caba77e6b/mozajudigeneme.pdfIn PDF document text
    • https://s3.amazonaws.com/bupaxomu/gantz_perfect_answer_streaming_ita.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ace523c2-43eb-4d71-a2d3-a187aa898ef7/9700074635.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f094d46-d9e8-4d61-82b1-cdf7a12e0ffe/28932227706.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ccec0703-b02c-4110-9628-9eba5a10e371/why_wont_my_apple_tv_remote_control_volume.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/93a40f9c-8e89-43eb-841d-4f400a6f17f1/page_break_preview_in_excel_online.pdfIn PDF document text
    • https://s3.amazonaws.com/nelizenejakarug/logo_quiz_answers_level_10_iphone.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1e0d0c53-38db-4844-8866-e7307c04067a/best_business_communication_courses.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015b47.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15B47 5416 bytes
SHA-256: 66dd75971a6900dd59af4c4af590beb46b25ac567ca62de5c0dd6d60ffa03d5f
font_01_sfnt_off00016d9f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16D9F 12288 bytes
SHA-256: 01e915ed3decfd7456613696a0ad0839cf953a2141fa3da563343bc31ff6daf8