Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9a5ee491a55437e…

MALICIOUS

PDF

82.6 KB Created: 2021-03-17 09:55:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7d92ff39fbd5dca8dae103d2be1ea388 SHA-1: e28d003afd137a952c5bc6aa093a1ccf04baac24 SHA-256: e9a5ee491a55437e3206f6c43745c03036c486bc6f7600c35c3cb0c36009036a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to deliver a malicious payload or redirect the user to a phishing site. The document body, though partially corrupted, suggests a lure related to home inspection costs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=how+much+does+a+new+home+inspection+cost
    • https://cdn-cms.f-static.net/uploads/4393026/normal_604e24b96d40c.pdf
    • https://cdn-cms.f-static.net/uploads/4412388/normal_6035b52e869e3.pdf
    • http://tumexade.22web.org/48545700715.pdf
    • http://susasami.22web.org/berlitz_intermediate_spanish.pdf
    • http://doxisodezezaku.iblogger.org/lgebra_y_trigonometra_con_geometra_analtica_ejercicios_resueltos.pdf
    • https://static.s123-cdn-static.com/uploads/4379030/normal_5fee480d69728.pdf
    • https://static.s123-cdn-static.com/uploads/4425784/normal_60016628d0daa.pdf
    • http://organic100.fun/can_an_ipod_nano_battery_be_replacedukopi.pdf
    • http://avit0.pro/43659107007u53vq.pdf
    • https://cdn-cms.f-static.net/uploads/4445118/normal_604dadcf983db.pdf
    • https://static.s123-cdn-static.com/uploads/4413231/normal_6003be3383904.pdf
    • https://cdn-cms.f-static.net/uploads/4386834/normal_601c644045260.pdf
    • https://cdn-cms.f-static.net/uploads/4495691/normal_5fe7e76fc2dfa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://namavorudil.epizy.com/rigivopepadeviradix.pdf
    • http://pomagupivedib.epizy.com/ankhon_dekhi_full_movie_filmyzilla.pdf
    • http://semimuwido.epizy.com/purple_hibiscus_symbolism_quotes.pdf
    • https://48bd7725-9370-4d18-884e-e75d7b70c9c4.filesusr.com/ugd/f241d9_9e7c110314394eb2ba0807e1814fb7e0.pdf?index=true
    • https://c827806f-f9bf-4fd3-a4ce-e487c020fa79.filesusr.com/ugd/6fd45c_008915a5de874fe7979ce7f73777141d.pdf?index=true
    • https://a1c9bafd-2917-4c1b-b79c-a4b44a941470.filesusr.com/ugd/f0f215_5cb45a5a018e42629410c158faec6221.pdf?index=true
    • http://wefazor.epizy.com/71909792284.pdf
    • http://rijogutigoxek.epizy.com/fifty_shades_of_grey_2_full_movie_online_free_greek_subs.pdf
    • https://5090c2af-253d-40c3-bfb7-942fc6db26b0.filesusr.com/ugd/0511f5_cf972ca4f1a34fe3be516ee03ccef9c3.pdf?index=true
    • http://xujogefup.rf.gd/html5_frameset_template.pdf
    • http://bugavujozi.epizy.com/12121728711.pdf
    • https://e9155d39-0f7d-4366-9ee8-34e17fe3d773.filesusr.com/ugd/9e05b8_2bac14bcdd194c4e9bfb9b54123c586b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010391.bin
b24f0891ee63f82d7cbadce6d3fe9f380e2cbc7d3ae8439097b0c22c6e64df9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x10391 5240 bytes
font_01_sfnt_off0001154c.bin
895cc89bf9477c38e0e8f814be34fa33ebbd2d5f0bc5cade60a902fea1663088
pdf-font-stream PDF embedded font (sfnt) at offset 0x1154C 11208 bytes