Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec818267136e73e9…

MALICIOUS

PDF

73.0 KB Created: 2021-06-06 21:21:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-24
MD5: f0cd1f10b225d1f1455910d7eaab9e98 SHA-1: 6a49dae425259e0cc3681e9bfb0d26c8a05a7dd2 SHA-256: ec818267136e73e9340e8979fbcf1ec73498b32e5696efd0e3493db1592c5bb8
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain. Heuristics indicate the presence of external URIs and a ML classifier flagged it as malicious. ClamAV also detected it as a phishing trojan. The document body, though heavily obfuscated, appears to be a lure related to 'Lord Shiva images wallpaper download'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://irlanc.ru/pbw?utm_term=lord+shiva+images+wallpaper+download PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4389599/normal_5ff897601e8bc.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4407057/normal_6057a6e1b3fdf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4530910/normal_60464a0f0cb3e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4376101/normal_5ffa386d7b737.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4379970/normal_5fdd89cdba85c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4470968/normal_5ff3bff9e9bf0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367300/normal_5fdb5547b5f0a.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • https://uploads.strikinglycdn.com/files/5d5d3c80-465d-44e5-9b1e-957ff8a04833/moving_down_along_a_given_budget_line_real_income.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7650b798-721b-437a-9b1c-fb0de2b1e53e/42225786009.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/86e7eb5c-fe7e-4a32-ac3f-6558dae589c2/tovojawus.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e99b39dc-3740-447e-b5bd-348f3622c1e8/17261327911.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/930d4229-ac09-4db1-a164-b128ea740cd3/xosilu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9b9848e6-88d2-4469-ad5a-04b7b8635aae/how_do_you_do_a_presentation_for_an_interview.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7e6b3acc-7219-499c-96b8-4eed61238f3a/what_is_cost_benefit_analysis_in_risk_management.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/482fad6f-1fdf-4dff-90f3-92e9d2c21f6f/dabewa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e0bbbdbb-7269-4576-9697-8f1fa23e98e5/kexetud.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7d7f2e18-0483-4f00-afbd-893239b0ef85/93761658542.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e55876bf-32b6-4f47-ac88-12e6e0919351/clicker_heroes_codes_2020.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0b30ddfe-1c80-4426-9c39-2f9ef6976a9d/what_the_last_books_of_the_after_series.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d4c2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD4C2 5464 bytes
SHA-256: ecc495eb4c3ac3274ebcba44aaaf2776516625f53a5f6fc42924eb187ae0fc32
font_01_sfnt_off0000e74b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE74B 10520 bytes
SHA-256: 80efcad5d3f360bf97a9bdae9a3b331600040b40c5d77ed78687ba032962b1c9
font_02_sfnt_off00010bbf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10BBF 2948 bytes
SHA-256: 9c2ef9320ec5aa1c39d971d9e2df5b2d03a73b867be58cf3504b6b57a0a01ccb