Malicious PDF — malware analysis report

Static analysis result for SHA-256 e5460223dfed4e13…

MALICIOUS

PDF

74.4 KB Created: 2021-05-09 02:37:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 9a24089ac04f329099371a1658bc3cc7 SHA-1: d3ec9dff20fde6f8c0e974a0d05060e3c1cfa3db SHA-256: e5460223dfed4e13ea0d92599f0fe25816615826b927c66b1b2f555357996904
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a critical heuristic firing for ClamAV detection. It contains an embedded URI pointing to a suspicious domain, 'ponafet.ru', which is likely used to host a phishing page or distribute further malware. The document body is heavily obfuscated and appears to contain junk data, suggesting it is not intended for human consumption but rather to exploit PDF parsing vulnerabilities or hide malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=george+foreman+grill+recipes+chicken+quesadilla PDF link annotation
    • http://suvexuvigijorup.22web.org/sintesis_protein.pdfIn PDF document text
    • http://joblanc.xyz/what_is_the_smallest_land_animal_on_earthpc1ve.pdfIn PDF document text
    • http://pexawegowe.mywebcommunity.org/apache_hadoop_tutorial_for_beginners.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4419412/normal_6042f1290d3c7.pdfIn PDF document text
    • http://maleev.online/89183311567wcvpp.pdfIn PDF document text
    • http://texegevesimiruv.22web.org/corpse_bride_piano_duet_sheet_music.pdfIn PDF document text
    • http://sekelenogake.getenjoyment.net/fund_accounting_journal_entries.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/bulolimepol/materi_bilangan_kompleks.pdfIn PDF document text
    • https://s3.amazonaws.com/feborobegibew/82764440373.pdfIn PDF document text
    • http://gopudagob.epizy.com/44687576083.pdfIn PDF document text
    • http://dakarudadujo.rf.gd/17204905629.pdfIn PDF document text
    • https://s3.amazonaws.com/tofizo/agneepath_1990_full_movie_free_300mb.pdfIn PDF document text
    • https://s3.amazonaws.com/rebesudanolo/comparing_philippine_money_worksheets.pdfIn PDF document text
    • http://nosigegu.onlinewebshop.net/sozoratofirovixulajuv.pdfIn PDF document text
    • http://runumap.rf.gd/14958111482.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d635.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD635 5592 bytes
SHA-256: 719c2f39b8c68be632808be7dd6b2a65fadaad79093054bcc47b53efcbeb3f47
font_01_sfnt_off0000e8ff.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE8FF 10988 bytes
SHA-256: b82e59f21c86adc079b9748ac2d869f905c8cea58e5088578bc84bbe739a55be
font_02_sfnt_off00010e14.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10E14 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3