Malicious PDF — malware analysis report

Static analysis result for SHA-256 e92cdf426c6ea260…

MALICIOUS

PDF

333.1 KB Created: 2021-03-08 20:51:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: a194e5c0b981e5872fc813dd7582de46 SHA-1: 658cd21ffc40f33575aad921e4cefb146fec838f SHA-256: e92cdf426c6ea2604ed3d2e0128e1492d223f029a113fc9b8aea73b931848ab4
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and an ML classifier indicated a high probability of maliciousness. It contains multiple embedded URLs, with at least one, 'https://gimoguvi.ru/123?utm_term=yakuza+4+hostess+make+cosplay+guide', appearing to be a lure for malicious activity. The document body is heavily obfuscated, but the presence of external URIs and the overall detection profile suggest it is designed to redirect users to malicious sites, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9941

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/123?utm_term=yakuza+4+hostess+make+cosplay+guide PDF link annotation
    • http://mamontov-net.cc/nosinegelupab9yeg.pdfIn PDF document text
    • https://vogaxuruxav.weebly.com/uploads/1/3/4/3/134352923/sepakanowasezevi.pdfIn PDF document text
    • http://xopivodez.22web.org/95407965311.pdfIn PDF document text
    • http://nowojikowelox.iblogger.org/brave_new_world_study_questions_chapter_1-3.pdfIn PDF document text
    • http://helplnstagramcontact6088756.com/75301333438or3kq.pdfIn PDF document text
    • http://jesofoma.getenjoyment.net/photoscape_x_review.pdfIn PDF document text
    • http://xonejalevesezom.sportsontheweb.net/kenmore_canister_vacuum_replace_belt.pdfIn PDF document text
    • https://tupivoxutod.weebly.com/uploads/1/3/4/4/134467409/gipuje_moveledija.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://uploads.strikinglycdn.com/files/9ed6775c-d508-4a8f-bc61-76da89cc0107/how_big_was_the_us_army_during_ww2.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/173c825c-af7d-4e31-8774-498376be42e3/maxatomapogosok.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/010e1970-7f43-4241-9152-54de745fa10a/what_does_the_moon_card_mean_in_a_love_tarot_reading.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/027d4890-ba45-4922-9c7c-f70079798bce/zokuvavumizepezud.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e3a98e0f-2182-48e7-91b3-8ca0aabf3131/59965430526.pdfIn PDF document text
    • http://xofinawudira.rf.gd/42001314035.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ca483f64-33c2-4299-880a-090e05d47e94/23688946752.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c071dcfd-f800-4d54-b5a3-279195dc7f1c/59619657057.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/59765305-8336-47a2-9b4a-00934925d668/lg_l90_d415_firmware_download.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004beda.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4BEDA 5656 bytes
SHA-256: b6c2a3a6149da6c0b0f537ec59bcfa8dc46956bb43cb58e8ff05f9f725ec0797
font_01_sfnt_off0004d219.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4D219 3720 bytes
SHA-256: d5ecec3e822993868ba70e247019bcdb656a9fee58d620eb93bc70658e929280
font_02_sfnt_off0004dd7c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4DD7C 14780 bytes
SHA-256: 1f16d604bd2108ce50bcf8b99ade680d9735fcc96a89736e67680253acf5145c
font_03_sfnt_off00050ca6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x50CA6 6724 bytes
SHA-256: d29f054450a02d487783ee6d5f1072fd2742f9f8800738d9e4576b0f46fdc0a2