Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef3a09de448b9084…

MALICIOUS

PDF

487.6 KB Created: 2021-04-14 18:13:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-25
MD5: fcb592a1ead49960b36c8623e87d29cb SHA-1: 90d132c3d557c56d8e3b14ed59805588760748c7 SHA-256: ef3a09de448b90848168c5e2bef5a17cdb70ddbefd11c713be9c4f6e36aaf02a
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ClamAV and an ML classifier, and it contains multiple embedded URLs that are likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to a 'strategy guide', which is a common tactic for phishing or malware delivery. The presence of external URIs indicates an attempt to download or redirect to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8858

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=chrono+cross+strategy+guide+pdf PDF link annotation
    • http://smartcoin.design/killing_floor_incursion_biotics_lab_walkthroughbsckn.pdfIn PDF document text
    • http://topchambre.xyz/ccna_1_answers_chapter_76qi64.pdfIn PDF document text
    • http://soul-felt.com/luvokazarufofefugadimuv65ff8.pdfIn PDF document text
    • http://megiloreb.mypressonline.com/23756837736.pdfIn PDF document text
    • http://ubsvp.com/xexedutukunegt3ng3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391326/normal_603c5e20cab7b.pdfIn PDF document text
    • http://leqqurint.online/how_to_light_tempstar_furnace5qbby.pdfIn PDF document text
    • http://study-english-04.space/2322634985m0lhq.pdfIn PDF document text
    • http://menudajuweka.22web.org/boxiwitomakatelu.pdfIn PDF document text
    • http://shlifovka-pol.website/329014647050cmp1.pdfIn PDF document text
    • http://chistohome.moscow/what_type_of_angle_is_360_degreesfgzut.pdfIn PDF document text
    • http://alfa-quest.ru/factor_rating_method_stepsw960b.pdfIn PDF document text
    • http://mufutekuson.getenjoyment.net/teaching_vocabulary_for_young_learners.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365620/normal_601faff24abd0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/webipejonavuv/how_to_describe_a_logo_for_trademark.pdfIn PDF document text
    • https://s3.amazonaws.com/xuzed/31762116530.pdfIn PDF document text
    • https://s3.amazonaws.com/towutoginadivu/intake_and_output_sheet_sample.pdfIn PDF document text
    • http://gajopule.myartsonline.com/kugamojamivisub.pdfIn PDF document text
    • https://s3.amazonaws.com/zumomasugipeno/zagibijutexibemozipi.pdfIn PDF document text
    • http://dirosulazab.rf.gd/24256161048.pdfIn PDF document text
    • http://zititerawori.epizy.com/date_format_unix_timestamp_php.pdfIn PDF document text
    • http://bemajisuvu.epizy.com/wadosubaz.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000753d3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x753D3 5392 bytes
SHA-256: 8847b0d99bf2b5b1c6f67e96ce234f560e55aaf7c8ef83d0da159257a0522cde
font_01_sfnt_off0007662c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7662C 11728 bytes
SHA-256: 8f8d5b6cc775373393846f0b7af70074b1d9f951e6ece5b39d36ba75d1d75712