Malicious PDF — malware analysis report

Static analysis result for SHA-256 ebcec99090a81369…

MALICIOUS

PDF

71.9 KB Created: 2020-12-26 22:36:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1d397d4f767b81c7a871954c4a0b4906 SHA-1: d47db24f680b6a79402645d5eb72e9b22396bfb5 SHA-256: ebcec99090a813695d7b8795f7a83376bc9d1cd34d61495aae9a1c0e07dcdfce
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URL that directs users to a phishing site, as indicated by the 'PDF_URI' heuristic and the ClamAV detection. The ML classifier also strongly flagged this PDF as malicious. The presence of embedded URLs suggests an attempt to redirect users to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/aws?utm_term=case+in+point+pdf
    • https://suxutusebosogu.weebly.com/uploads/1/3/1/3/131379987/1991949.pdf
    • https://cdn.sqhk.co/kuzosexiwugu/TRpvktp/logo_quiz_answers_level_46.pdf
    • https://cdn.sqhk.co/pavujakorige/UWibigp/jepopufokupisis.pdf
    • https://cdn-cms.f-static.net/uploads/4414864/normal_5f964573c5cc9.pdf
    • https://static.s123-cdn-static.com/uploads/4481695/normal_5fe55fe57930b.pdf
    • https://cdn.sqhk.co/daboxazile/SFmJOHj/dekekudijuwokobexu.pdf
    • https://static.s123-cdn-static.com/uploads/4420924/normal_5fe1d9048f617.pdf
    • https://cdn.sqhk.co/vipabumumiw/6njbkjf/mulikodol.pdf
    • https://cdn.sqhk.co/netesatova/uEigEgg/flight_simulator_3d_airplane_pilot_game_download.pdf
    • https://lanasasaf.weebly.com/uploads/1/3/0/8/130815311/sesesivufaxoma.pdf
    • https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/zobugoralutu.pdf
    • https://cdn-cms.f-static.net/uploads/4415061/normal_5f9ef07bf2816.pdf
    • https://cdn.sqhk.co/xivumatozo/mUrgdja/vuwije.pdf
    • https://cdn.sqhk.co/dejenuluzew/X3K7Uig/77640515353.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wenobagupexekap/gujojijowesugiki.pdf
    • https://s3.amazonaws.com/vuraradaso/24989263196.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ddce.bin
51e406968c867157b04f290a3a5166851684e9976244dfc67e6f333a27c7976d
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDCE 4812 bytes
font_01_sfnt_off0000ee41.bin
e9ccc9c07918b3e9c18190b0247bab6ed25d844b06a134812d9d667c6ae9f25d
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE41 10684 bytes