Malicious PDF — malware analysis report

Static analysis result for SHA-256 e88f87194971f888…

MALICIOUS

PDF

75.3 KB Created: 2021-05-22 10:44:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: acafdb0bd07e73dc8fd6c8b6e31e3840 SHA-1: 751863419182eb1ce871235e0570903ac8669743 SHA-256: e88f87194971f8885e92b29b5c5ea52c8305dbe2fe8818fac68138a7c55802e8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic indicating an external URI, which points to a suspicious domain. The document body, though heavily obfuscated, contains references to 'Kahlil Gibran short stories pdf' and 'wkhtmltopdf', suggesting a lure to disguise the malicious intent. The ML classifier and ClamAV detection strongly indicate maliciousness, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=kahlil+gibran+short+stories+pdf PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4374857/normal_60139462f124a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4371240/normal_5fc760e4140fb.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4471690/normal_604b0c00c6b13.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4488581/normal_6023da2a45e1e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4500887/normal_5fecef622a8d7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4415065/normal_5fd66780e06db.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4488137/normal_60113be3c0521.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4494431/normal_5ffb253edb4cd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4454429/normal_603cccbfd7c48.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4496853/normal_5ff4ce90532df.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/b2fec1a3-e86a-4414-b470-c92332b487c8/types_of_phonics_instruction.pdfIn PDF document text
    • https://s3.amazonaws.com/rafiralexezol/agile_coaching_book.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2aacc722-f8c9-442b-85af-7f7774474f78/sony_cyber-shot_rx100_iv_price.pdfIn PDF document text
    • https://s3.amazonaws.com/kijelopazekune/vunadarisadagerajexukixep.pdfIn PDF document text
    • https://s3.amazonaws.com/tonemakopinibem/cruyff_shoes_size_guide.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eea41ce6-9223-46c9-86ee-3924461cd075/92473426728.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/459343b7-1a14-487d-9ff7-8ce036773a55/neverending_story_big_dog_name.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4699b0bc-2243-448a-a236-a38dccc1abcd/itil_v3_foundation_certification_body.pdfIn PDF document text
    • https://s3.amazonaws.com/perurulexi/e39_auto_to_manual_swap.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1eeae11d-88d1-4e58-968e-9231d818557f/foreign_direct_investment_books.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eab7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEAB7 5412 bytes
SHA-256: f7765d7e130c1df2ac60895404182ee7176fec9b29453e728e1b09453111adfb
font_01_sfnt_off0000fd16.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFD16 10372 bytes
SHA-256: 25d27a5e6a088e02cf52fe04faf2812b58d166188020e87690876cb353679e92