Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee03735796e5963e…

MALICIOUS

PDF

81.6 KB Created: 2021-04-04 03:04:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 4727a40aea3ac4b264696c7a3fe4dd5b SHA-1: b6cc0ddbdad11e79f291cc84f6656f49afa0c022 SHA-256: ee03735796e5963eb17b3e3d97dd4073c2567588cf5beb8e54e69610bd346ef5
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to 'leonvi.ru', which is flagged as suspicious. ClamAV detection and ML classification strongly indicate maliciousness, classifying it as a phishing trojan. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, a tool often used to create PDF documents from web content, further supporting the lure to an external URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=guide+gear+cargo+pants PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4419452/normal_601beb852426c.pdfIn PDF document text
    • http://jewlgems.com/como_conseguir_lingotes_de_oro_candyjpbua.pdfIn PDF document text
    • http://b4shop.icu/animal_english_song_freehaduh.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403410/normal_6003a9944af6b.pdfIn PDF document text
    • https://cdn.sqhk.co/jowibigodene/eHjgiaN/lejol.pdfIn PDF document text
    • http://mazafaka69pussy.online/balearia_palma_formentera_directour3hd.pdfIn PDF document text
    • https://cdn.sqhk.co/bisulalu/h4uieih/vubavusudinugigud.pdfIn PDF document text
    • http://sugoxebojun.getenjoyment.net/88349494613.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393893/normal_5fee8f6c77206.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4407064/normal_5fcf50204f3fa.pdfIn PDF document text
    • http://jonotijero.medianewsonline.com/bebixosafolugot.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zesixefe/how_to_use_canon_f_718sga_scientific_calculator.pdfIn PDF document text
    • https://s3.amazonaws.com/batoragubukepo/melim.pdfIn PDF document text
    • https://s3.amazonaws.com/jefobexapulow/xozeseraraxax.pdfIn PDF document text
    • https://5a98ae10-8c7e-48da-b83f-9bcbc644cfa3.filesusr.com/ugd/9a8764_53888c3c2b964ff29c9f469110ec4f2a.pdf?index=trueIn PDF document text
    • https://4b4ea461-5266-411b-8735-d5290551f550.filesusr.com/ugd/7fedcf_511ae59c41a94a3599358a946eb7f046.pdf?index=trueIn PDF document text
    • https://03df18d0-0a94-4077-8b44-1f3cf8b7c870.filesusr.com/ugd/23a6c3_76893804b2eb46b6b105846d86eedfd3.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/megujobemegor/baby_shark_original_video.pdfIn PDF document text
    • https://010f2e21-25ca-4560-806d-08cbbb7c7db1.filesusr.com/ugd/74a852_5d598b124d1a4b8c9c9802ca514543e5.pdf?index=trueIn PDF document text
    • http://vuzuwukef.atwebpages.com/marx_capital_and_the_madness_of_economic_reason.pdfIn PDF document text
    • http://zowofiz.myartsonline.com/stepwise_regression_spss.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebce.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEBCE 5240 bytes
SHA-256: 566182fe26ca1f7bede75a82ebe69d3ac11f0fc940edf142d3651b42aeb78f66
font_01_sfnt_off0000fdb6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFDB6 11216 bytes
SHA-256: 8d6e091ae73754aa76c0e48ae2a9254e25e9c4199e256f7160f19cab4698f17c
font_02_sfnt_off0001242c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1242C 16140 bytes
SHA-256: 1ffca1ef16be5e2ec436e77f9211a88ad3199dc781cb76600401cc2e2c7dce6d