Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef396d35fe0b21fb…

MALICIOUS

PDF

371.6 KB Created: 2021-04-01 13:44:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1d36cf4d0b7279a6018a1f7a4bff7fa9 SHA-1: bed79fa428a1a0ac700c0751962e1c8360349296 SHA-256: ef396d35fe0b21fbcce06d9cdbb1f5099c7df61802b451c2c397dd12a0f92750
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV with a Pdf.Phishing.Trojan signature. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a phishing or malware distribution site. Although no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to exploit users through a malicious link, aligning with phishing tactics.

Machine Learning

  • Nyx PDF Classifier clean score 0.1680

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=%25D8%25A7%25D9%2584%25D9%2581%25D9%258A%25D8%25A9+%25D8%25A7%25D8%25A8%25D9%2586+%25D9%2585%25D8%25A7%25D9%2584%25D9%2583+audio
    • https://vonuxunip.weebly.com/uploads/1/3/4/3/134377821/26142.pdf
    • https://static.s123-cdn-static.com/uploads/4484364/normal_5ff37f471b389.pdf
    • https://cdn-cms.f-static.net/uploads/4465131/normal_60599976c88cb.pdf
    • https://lififamofupuge.weebly.com/uploads/1/3/4/3/134317858/3138066.pdf
    • https://static.s123-cdn-static.com/uploads/4479925/normal_5fdefd79ebfeb.pdf
    • https://xavixevoke.weebly.com/uploads/1/3/4/5/134590279/fosolon.pdf
    • http://salogogudezofa.iblogger.org/carer_recognition_act_2010.pdf
    • https://togezajotutev.weebly.com/uploads/1/3/0/8/130874352/xajito.pdf
    • https://cdn-cms.f-static.net/uploads/4448547/normal_605f3583ba1c9.pdf
    • http://kiwirixup.22web.org/literature_review_on_bambara_groundnut.pdf
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.indictrans.org
    • http://xigavuda.rf.gd/the_misfit_of_demon_king_academy_japanese_name_manga.pdf
    • http://lodafudamisov.epizy.com/probability_tree_diagrams_gcse.pdf
    • http://ribibepope.epizy.com/begonia_formosana_f_albo-_maculata.pdf
    • http://famovuwozagomo.epizy.com/dagogobube.pdf
    • https://26c1613e-5d28-4fa3-89cb-3d2c9ab59faf.filesusr.com/ugd/fe83c3_00099fa20e0548139b7c828db7af503e.pdf?index=true
    • http://vibiwarufade.rf.gd/metenagom.pdf
    • http://muwutumob.epizy.com/metewig.pdf
    • http://nebugobebakejef.rf.gd/gerepuzaxejedolegoxeg.pdf
    • https://9b321a86-0615-40a7-b684-6dced782f4cc.filesusr.com/ugd/e3cae3_1914e921472942fb947f97e9a412d32e.pdf?index=true
    • http://nozafawuronixe.epizy.com/59395394755.pdf
    • http://duxuramubot.epizy.com/87292592777.pdf
    • https://b47237a6-1880-4d87-9598-f01162bab054.filesusr.com/ugd/1fe0ea_24f7ea6cc1f14751a8310266ea5e3ac6.pdf?index=true
    • http://gefimosikalet.rf.gd/rewenozor.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_011_off0004f0d9.bin
0232da31854c9a93f701e2463010822276fa1999d71527b0cc3d078ee68bfa4d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F0D9 8716 bytes
stream_015_off00056e84.bin
84b20863b6dcf95c7d0df61161cb666e9d7a467ac44eb46e14da2ecc34c228ea
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x56E84 35884 bytes
font_00_sfnt_off000482ec.bin
374f4545ff1b4dfa8a4e3bf0dfff49d03a63e9ed38048f8613cbde9972515e76
pdf-font-stream PDF embedded font (sfnt) at offset 0x482EC 4972 bytes
font_01_sfnt_off0004949b.bin
4bacd80cd552cb2fe474a987a8c1a7344433bde55d2462b4c5e7e0cf16e8f582
pdf-font-stream PDF embedded font (sfnt) at offset 0x4949B 4416 bytes
font_02_sfnt_off0004a3a4.bin
c181b71675ab69f812e6cbdc3b57579d2876a009b95ceea16277c751dff0c199
pdf-font-stream PDF embedded font (sfnt) at offset 0x4A3A4 4932 bytes
font_03_sfnt_off0004b445.bin
638170e14c032be6a82b11f8a70058add03a2176c12999d57f4a377ab7ba49f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B445 5340 bytes
font_04_sfnt_off0004c58d.bin
b06cdfe28969e2116bb82274ddfb39d2832d5f25e39e16110795d23aef5b410a
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C58D 4752 bytes
font_05_sfnt_off0004d66b.bin
d4cda5a9ecb2558448f754249352cd4d73a8f7efff03060ee9a54ebf713292d1
pdf-font-stream PDF embedded font (sfnt) at offset 0x4D66B 2604 bytes
font_06_sfnt_off0004e184.bin
c6b7fa945c60b8843736b022094b55388116d9bca3b0b4cb0df282c78257ab5e
pdf-font-stream PDF embedded font (sfnt) at offset 0x4E184 4116 bytes
font_08_sfnt_off00050962.bin
e5c08da0fb7ee451d06817c5e101f59fdb5df8be45e164a732ed3b42f5e45e7f
pdf-font-stream PDF embedded font (sfnt) at offset 0x50962 6056 bytes
font_09_sfnt_off00051cf2.bin
734ac3111c0175fa692039636b72c001b6c74bcca676b62c64fc7ebc2e8b1ab7
pdf-font-stream PDF embedded font (sfnt) at offset 0x51CF2 19124 bytes
font_10_sfnt_off00055549.bin
40f583568d7aa82d6a8c0eec6af509969df2a6871c9c3dc54a21b82d85d8621a
pdf-font-stream PDF embedded font (sfnt) at offset 0x55549 17232 bytes
font_12_sfnt_off0005aacc.bin
5e8a52448601d86d2c57a7b3712d41b89cb318a61973bd0ef3bc2cc6715ba55a
pdf-font-stream PDF embedded font (sfnt) at offset 0x5AACC 3560 bytes