Malicious PDF — malware analysis report

Static analysis result for SHA-256 eaa8195911b7c4cf…

MALICIOUS

PDF

75.0 KB Created: 2021-03-24 04:51:30 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7df84af26b2e508c91a7d1e10edf2357 SHA-1: dc4e841c63518dcfa1ee410ad7d745cbc1b8b7a7 SHA-256: eaa8195911b7c4cf1a004612f8d7e376405c81e8c8b340dc7779e14af3d6cf03
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that appears to be part of a phishing lure, as indicated by the 'keyword' parameter in the URL and the ML classifier's high confidence in detecting malicious content. ClamAV also detected this file as a phishing trojan. The document body, though heavily obfuscated, contains text related to the URL, suggesting an attempt to trick the user into visiting the malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9956

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/wix?keyword=eeventmanager.app+what+is+it
    • https://cdn-cms.f-static.net/uploads/4416935/normal_6052b019e02b4.pdf
    • https://cdn-cms.f-static.net/uploads/4468261/normal_6014c20ae846f.pdf
    • http://rubewox.sportsontheweb.net/76266704747.pdf
    • https://static.s123-cdn-static.com/uploads/4408009/normal_5ffcfc17c326f.pdf
    • https://cdn-cms.f-static.net/uploads/4366055/normal_6027456f2666e.pdf
    • http://takaweri.mywebcommunity.org/77018837839.pdf
    • https://cdn-cms.f-static.net/uploads/4450345/normal_5fe8ebba0a468.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/95bcf005-5948-42cc-b7af-ba259bea1c6d/the_choice_trailer_song.pdf
    • https://s3.amazonaws.com/jipowumat/fanudepoku.pdf
    • https://s3.amazonaws.com/lazolu/que_es_una_composicin_literaria.pdf
    • http://madigekole.onlinewebshop.net/xemiduvuvesokedirolur.pdf
    • https://s3.amazonaws.com/rogugagatuf/swiffer_wetjet_heavy_duty_mop_pads.pdf
    • https://uploads.strikinglycdn.com/files/6105d301-0478-4ac7-869b-87a21d1e24ef/ps3_dualshock_controller_battery_replacement.pdf
    • https://uploads.strikinglycdn.com/files/c14b6882-9fa1-4753-acb4-12f5bb28961b/how_to_reset_a_frigidaire_stackable_washer_and_dryer.pdf
    • http://xikusaduxofi.atwebpages.com/tegekifufogulotoz.pdf
    • https://uploads.strikinglycdn.com/files/fe3de088-76d9-4d00-9042-17dc37b64b62/junior_parkour_classes_near_me.pdf
    • https://uploads.strikinglycdn.com/files/ddcb72b2-bb88-4aa2-9498-19f9d5cfebea/logunepibawuxexawigul.pdf
    • https://uploads.strikinglycdn.com/files/56f94854-11fd-44fd-b456-8e8413ff38d7/27696215162.pdf
    • https://s3.amazonaws.com/wifiduxezo/ritedonatuninuxiv.pdf
    • https://uploads.strikinglycdn.com/files/b4f6425b-f417-4aca-b6d8-778c2b029062/language_in_mind_an_introduction_to_psycholinguistics.pdf
    • https://uploads.strikinglycdn.com/files/6741fe46-ea7c-4f0c-a42b-9416e423d019/ec8552_computer_architecture_and_organization_syllabus_for_ece.pdf
    • https://uploads.strikinglycdn.com/files/84caa6ba-d1fb-41eb-a520-dd80246265eb/how_to_change_white-rodgers_thermostat_to_fahrenheit.pdf
    • https://s3.amazonaws.com/jusuberu/kala_bazaar_movie_full_hd.pdf
    • https://uploads.strikinglycdn.com/files/fde13652-301b-4a00-b412-926c01703f6b/ap_physics_1_barrons_vs_princeton_review.pdf
    • http://rofuvawitarul.atwebpages.com/candide_by_voltaire_characters.pdf
    • https://s3.amazonaws.com/telasebisu/fewitukelefugivilafanuz.pdf
    • https://s3.amazonaws.com/vajefam/li_file_khng_in_c.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e4ff.bin
9965e70a82d5220fefdee67a0e5f3ab9d9221b94280354804ed42e788188e623
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4FF 5344 bytes
font_01_sfnt_off0000f71d.bin
de00e4afae3aa862b24535d809e25b3eddee4e599b0a38535ffedf5b13dadfb4
pdf-font-stream PDF embedded font (sfnt) at offset 0xF71D 11556 bytes