Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb1fa0a9d17d7c79…

MALICIOUS

PDF

122.1 KB Created: 2021-05-18 10:16:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5cec28cb9d2b422248bb5fdd6abf5084 SHA-1: d858a0611683de8c657506bf9385fbd67346c105 SHA-256: eb1fa0a9d17d7c79ef14994cce4282ab36542b99cc4ff9cf9fb72379e08b6136
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The presence of an external URI pointing to 'pistant.ru' suggests a phishing or malware distribution lure. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a phishing attempt, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pistant.ru/uplcv?utm_term=what+does+adversity+quotient+mean
    • http://xn--clinicaquirogavilario-vbc.com/wp-content/plugins/super-forms/uploads/php/files/ggh0jjvo7amhdg7ppau6c77n93/43726566473.pdf
    • http://119hero.kr/userData/board/file/13515177409.pdf
    • https://akdenizokullari.k12.tr/wp-content/plugins/super-forms/uploads/php/files/4rcr208l6ij6mm2hib27tuctkk/59270186348.pdf
    • https://agsposure.org/wp-content/plugins/super-forms/uploads/php/files/16902635fd4019880ad4825281e6e4b4/zovapowasokojubuzuzuja.pdf
    • https://www.coconutlodge.com/wp-content/plugins/formcraft/file-upload/server/content/files/160760832d1c9b---xogawipifinopigitenuro.pdf
    • http://www.radioemka.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606fbd7d84424---xugufigaforexedurag.pdf
    • https://angkortaxiservice.com/userfiles/file/24306043284.pdf
    • http://averon.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1607ebf0ef3884---90108285161.pdf
    • http://www.fullmooneye.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609408b424cd0---23335386721.pdf
    • https://sckstone.com/wp-content/plugins/super-forms/uploads/php/files/2773d312f7ffb763155fc3d8f1d72a5d/80436477977.pdf
    • https://www.siemers-deutschmann.de/wp-content/plugins/super-forms/uploads/php/files/d1fv08v06q1vofhu0tpfkbqamq/70968002907.pdf
    • https://chicagoportablexray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16098329dcc80b---lavigoviv.pdf
    • https://cbolean.com/wp-content/plugins/super-forms/uploads/php/files/rgrs6p30h8tcnvprphhcs17rl3/6524228179.pdf
    • http://mirembeestate.co.ug/wp-content/plugins/formcraft/file-upload/server/content/files/160733ca1505cb---sadekajab.pdf
    • http://allycatering.com/userfiles/sirelejizuwijam.pdf
    • https://ahreco.com/uploads/news_file/xakirivixoputixijarasixex.pdf
    • https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607dd62660161---60975900651.pdf
    • http://fontawesome.iohttp://fontawesome.io/license/
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000197d5.bin
a63dc7203ceba2031beaf1d50b83973ffdd0483474384fa5780efc3deacec6ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x197D5 1696 bytes
font_01_sfnt_off00019fff.bin
e56387057adf05c420d98575527aa8c673233eaef94a2c3248b957c9d3827210
pdf-font-stream PDF embedded font (sfnt) at offset 0x19FFF 5332 bytes
font_02_sfnt_off0001b20b.bin
931707b7dd4e0491c4af93e864eb73c294683bf3da633afba6102d1c961bccdd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B20B 11776 bytes