Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed1b0dd733fcfd38…

MALICIOUS

PDF

78.7 KB Created: 2021-03-31 02:10:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c92a88bd213d59af9950436e859f4226 SHA-1: 9b3f4a7930cc8f8a8dcd3ed397c4b3f996af213f SHA-256: ed1b0dd733fcfd386f2f5f45d4618f48f22226e7d31fb4e72d4039ffe28042b1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with the primary one being 'https://lozipotod.ru/award?keyword=an+inspector+calls+key+quotes+and+analysis+pdf'. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest an attempt to redirect the user to a malicious site, potentially for credential harvesting or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=an+inspector+calls+key+quotes+and+analysis+pdf
    • http://lisujaden.22web.org/64842435554.pdf
    • http://jixelaxoli.66ghz.com/12920340510.pdf
    • http://nukobom.22web.org/black_american_movies_2018.pdf
    • http://fuvagezilavez.mygamesonline.org/vomevazemibuximijikuzubov.pdf
    • http://vabuxobetarewo.22web.org/73258116527.pdf
    • http://wapajojakazewi.iblogger.org/benokilewemozomumekoneme.pdf
    • https://pipabujul.weebly.com/uploads/1/3/2/6/132680817/9964183.pdf
    • http://nogeturafo.sportsontheweb.net/busesivawo.pdf
    • https://bazojosazim.weebly.com/uploads/1/3/6/0/136086377/setomipifebud.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://jupukatovukupi.rf.gd/94535714789.pdf
    • http://siwebojik.epizy.com/bafufemu.pdf
    • https://uploads.strikinglycdn.com/files/e7b7f81d-bcc3-4266-bc69-fcba19de6891/howard_leight_impact_sport_tactical_electronic_ear_muff.pdf
    • http://zopiselewanut.epizy.com/fizoxewiku.pdf
    • http://zebezepewit.epizy.com/aspen_plus_software.pdf
    • http://zopuraxikesu.epizy.com/balanza_de_pagos_estados_unidos.pdf
    • http://fefisapuvekebi.epizy.com/bepanah_pyar_title_song_ringtone.pdf
    • https://uploads.strikinglycdn.com/files/bcbe8ae1-2309-48aa-a2f2-d2824c3edcf5/rerakurezonusikegut.pdf
    • http://kamuwizedelas.rf.gd/62575727134.pdf
    • http://positajugopisu.myartsonline.com/vocabulary_words_with_meaning_in_kannada.pdf
    • https://uploads.strikinglycdn.com/files/e4e95c49-9932-4250-8b22-16d02f19fcbb/how_to_find_google_location_history_on_iphone.pdf
    • http://mekasesajiw.onlinewebshop.net/shatter_me_meaning_in_english.pdf
    • https://uploads.strikinglycdn.com/files/791d856b-acf6-4967-b822-365dcf9ee0a5/what_to_cook_that_will_last_all_week.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f612.bin
e83d2230af159693a7c8338231759875cc1de83465b8a5a34efe6a155b7514e0
pdf-font-stream PDF embedded font (sfnt) at offset 0xF612 5428 bytes
font_01_sfnt_off0001089f.bin
ccbf8c46bea5838ec76e32040d10b899b8dd2b9fd8fca89afe34520d76de0d7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1089F 10924 bytes