Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee35722ba8b3d92c…

MALICIOUS

PDF

72.0 KB Created: 2021-03-01 21:41:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-26
MD5: bdd43249f766876b4fedcd6a2f5527e9 SHA-1: 253c1c8e4782f9ddd395edabde661e2f24564331 SHA-256: ee35722ba8b3d92c8125ef3b66535e829feab8be02a36920c42d826b4801de53
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The document body, though partially corrupted, contains text related to 'medal display case michaels' and the authoring application 'wkhtmltopdf', suggesting a lure to a potentially malicious website. The presence of embedded URLs, particularly 'https://gimoguvi.ru/wix?keyword=medal+display+case+michaels', further supports this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gimoguvi.ru/wix?keyword=medal+display+case+michaels PDF link annotation
    • http://smartradiobf.ru/teganotidawatamawijqkhh6.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4415930/normal_5ff1d853e424d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4373992/normal_602ea21e691a9.pdfIn PDF document text
    • https://cdn.sqhk.co/resilano/iijeTid/wasixudajulatejulin.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4528780/normal_601a20a6c7fc7.pdfIn PDF document text
    • https://cdn.sqhk.co/zukuxenopo/dEKYTsM/lexifofikagano.pdfIn PDF document text
    • http://galoomer.online/32852018335sfjp.pdfIn PDF document text
    • http://cmbespaceclient.xyz/bhojpuri_gana_video_mp4_2019_hd56t4g.pdfIn PDF document text
    • https://cdn.sqhk.co/mipekakiri/aWz8jhD/rirovazo.pdfIn PDF document text
    • http://vas-rem.ru/planetary_gear_ratio73162.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/lunojol/email_template_esl.pdfIn PDF document text
    • https://s3.amazonaws.com/miwolezedubujoz/fringe_complete_series.pdfIn PDF document text
    • https://s3.amazonaws.com/gavexilatuvitaz/detox_diet_plan_for_a_month.pdfIn PDF document text
    • https://s3.amazonaws.com/voxulija/vetobogir.pdfIn PDF document text
    • https://s3.amazonaws.com/vidadaviwal/3_credit_reporting_agencies_freeze.pdfIn PDF document text
    • https://s3.amazonaws.com/jebupofedijakuk/materi_kuliah_akuntansi_keuangan.pdfIn PDF document text
    • https://s3.amazonaws.com/tojazudibumogab/venidokunemuxisewax.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc1f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDC1F 5324 bytes
SHA-256: c085f52f02f17221ef5c1172e511eb94dac74155d945ca73acbd50614980f87d
font_01_sfnt_off0000ee2a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEE2A 10688 bytes
SHA-256: 25d4de55e08d78293e1b0429e8abc799483371edcef6a947b52cba7cce34909a