Malicious PDF — malware analysis report

Static analysis result for SHA-256 e94cada2c87c9670…

MALICIOUS

PDF

109.7 KB Created: 2020-12-18 14:46:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: 5c42e5603af0cf73290476ab20cfe3bf SHA-1: dba93220e2393bc59cee619ed81cb118d2ec9b22 SHA-256: e94cada2c87c9670b0e74e4574fa34d6428ec666b1590cee25d2ac8eb6a2da3d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/strik?utm_term=tian+mi+mi+translation PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4420589/normal_5fd8b4ea821f4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4421778/normal_5fba4be66158e.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4503050/normal_5fbd081e0d6a6.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/ad384fc8-46e2-4ede-b9b3-e5fdd7552a98/words_that_start_with_a.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b09bf96-7c5f-4c07-acf9-eb51f277558a/mckinney_trade_days_2020_schedule.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/006441f8-ed5d-4274-9f00-d316c6d60e54/male_tank_tops_for_sale.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5213905d-ece8-4f39-939a-213adf189e79/saxon_math_6_5_tests_and_worksheets.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7fa678d-e59a-481a-a36c-5e1acfdffadd/pigizog.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7af7dd44-590b-4382-9ee1-80016612c97c/gavakugib.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1a48a254-b0aa-4907-9f20-0a629f87453b/fastest_way_to_shilo_village.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e6e71e75-7238-4993-a590-f9f6ab1ec2c9/what_is_rhodium_plated_over_brass.pdfIn PDF document text
    • https://s3.amazonaws.com/nezanurugega/tumevusafolinofopadariv.pdfIn PDF document text
    • https://s3.amazonaws.com/sezewu/xamakelasevilegulepiw.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6c510533-637a-4322-93ef-377cbd470feb/59086445278.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/572e57aa-fef9-4258-b5a5-ea9f21df4af2/64138528218.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off00016c0b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x16C0B 25316 bytes
SHA-256: 4efcd551e832ae81112ba54474513cb839bad3da576c17bccea464153e99d79d
font_00_sfnt_off0000e48a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE48A 20080 bytes
SHA-256: c3a558780e500d0121986f1b8846196ca29a1f6e8cf43f784d62b2f2b3db8e8c
font_01_sfnt_off0001240d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1240D 4452 bytes
SHA-256: b02cecc38efa5c1b61af097e1228a6f2da38466563439edbe9d6f14dc0b47495
font_02_sfnt_off000132f0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x132F0 20032 bytes
SHA-256: 18a361f4cb72ca0997fe1e1494e45b32b1c8373b4253018b1eb0b8af2c3a4bed
font_04_sfnt_off000198eb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x198EB 4324 bytes
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176