Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb90cdfb8fc0cf40…

MALICIOUS

PDF

91.1 KB Created: 2021-03-07 23:24:28 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: c799a573f394c1d4fc7eb680a4c3c2f4 SHA-1: 20858977fc264c0ed868852e24234f624bc59edb SHA-256: eb90cdfb8fc0cf40016d71a9402dc157efe3a6a2ee15ed61697f5041228d0285
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=bhagavad+gita+chapter+16+verse+11 PDF link annotation
    • http://50offstore.pro/94329935791xsgh7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4500417/normal_603874927fba4.pdfIn PDF document text
    • http://natur-green.fun/old_navy_canada_online_shoppingqqb38.pdfIn PDF document text
    • https://cdn.sqhk.co/mujexoxa/AjbdROS/5803839408.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4380384/normal_603f977add0e8.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4401716/normal_5ffe05a81690c.pdfIn PDF document text
    • https://cdn.sqhk.co/xipepovivik/cs9YEhh/rivudijese.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4420592/normal_6013339b911f3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412173/normal_600bf982d9d63.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4481406/normal_60202a322ce42.pdfIn PDF document text
    • https://cdn.sqhk.co/dofexoxev/Y4Fjjje/line_disney_tsum_tsum.pdfIn PDF document text
    • http://opsnatur.fun/11484817351cpu7g.pdfIn PDF document text
    • https://cdn.sqhk.co/pifonode/wIzgdge/toca_boca_pictures_of_characters.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://uploads.strikinglycdn.com/files/18a8c797-c99c-4868-9897-3fc235c933bb/bokoxone.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5610993f-cd1c-4c1f-bcd5-26503ca81ef3/xizanijefa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7873ca16-3bcf-465f-94c0-0c0bb161da7c/laserjet_p3015_printer_specification.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/492d1759-8069-4659-a0ac-f73eb2425512/zozadaz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a7e88a4b-2ae3-47ab-a715-920594dcc94f/what_is_management_by_objectives_in_hrm.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2ba75138-0033-4240-9323-0c9c82a935c5/wisonasixega.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bdffe7f3-9c65-4675-ba1d-b10d0368dad7/apps_to_use_with_schwinn_ic4.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/22c44312-c929-48ca-bc99-7934980450ca/vapujuwoxizilela.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff46.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFF46 5616 bytes
SHA-256: b67d730c4d2e605b391c9904f1e22f1c093108434a4f09a6e014ec5e9680ff1b
font_01_sfnt_off00011267.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11267 3740 bytes
SHA-256: 6ce3ed3d0cf168fbf74d6eb321148d5efc31cda11559831b77020f7d4c9f4c8c
font_02_sfnt_off00011de2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11DE2 11804 bytes
SHA-256: 3630f7fdd2651d1329f8dd538a75ee5f8fdc9fce0a0d83ab6de05f0329b8389d
font_03_sfnt_off000143dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x143DC 7552 bytes
SHA-256: 4b4503f9625e4011261ad5d1e96d999b58116c6c0793a9139ede10bb44802e35