Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8fd95fc11d5358a…

MALICIOUS

PDF

67.6 KB Created: 2021-03-15 16:39:10 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 04f9e94e11c825558973db4af5a0707b SHA-1: 9e58d148589f92f773b37a8bd17d2087c26f281e SHA-256: e8fd95fc11d5358a9bae396dc499e70cdad0fd496f092fdf912a1ce08c987af8
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://xajibur.ru/aws?utm_term=apollo+twin+mk2+quad+usb', which is likely part of a phishing or scam attempt. The document body, though heavily corrupted, suggests a product name, possibly to disguise the malicious nature of the link. No scripts were extracted, but the presence of external URIs and the malware detection strongly suggest a phishing or credential harvesting attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8462

Heuristics 3

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/aws?utm_term=apollo+twin+mk2+quad+usb
    • http://bapupozizevose.22web.org/fofamufuxepanir.pdf
    • https://cdn.sqhk.co/lokabawopup/javNgiT/download_game_race_max_mod_apk_unlimited_money.pdf
    • http://nunejabu.scienceontheweb.net/mcdonald_s_menu_with_prices_sa.pdf
    • http://xogunajeraxuda.mywebcommunity.org/59140116846.pdf
    • http://pixidilivutep.medianewsonline.com/jetopinunup.pdf
    • https://cdn.sqhk.co/fudamozomeb/MPHbdjc/50276016926.pdf
    • http://wanulutipumik.iblogger.org/afrikaburn_2019_survival_guide.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f58261e3-eaa6-4ba8-ba7a-6c7a597c3514/walmart_grocery_app_wont_load_favorites.pdf
    • https://s3.amazonaws.com/kujapomib/15240009543.pdf
    • http://wufagezigedo.onlinewebshop.net/elementos_radiactivos_de_la_tabla_periodica_y_sus_aplicaciones.pdf
    • https://uploads.strikinglycdn.com/files/c887ac72-f7e6-46b5-a5df-729665bcb0b4/94721592439.pdf
    • http://japinoxizidunub.myartsonline.com/bateduvixesojeb.pdf
    • https://s3.amazonaws.com/sazomo/bkash_app_old_version_2018.pdf
    • https://uploads.strikinglycdn.com/files/58da979c-94b1-45eb-8ec8-6925aa020370/88777109592.pdf
    • http://dufobilubaxa.rf.gd/sutuxukowujumixapexa.pdf
    • http://zisoramemib.rf.gd/xuvokebax.pdf
    • http://bejiteviv.epizy.com/37565579243.pdf
    • https://s3.amazonaws.com/patilawasu/morusazizimolawalo.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f635.bin
e389940203a80128c5445d3ec812f84cf33dd1ea3ae29c51c20cf18ce5c088cf
pdf-font-stream PDF embedded font (sfnt) at offset 0xF635 5552 bytes