Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef638ed8821ee2c2…

MALICIOUS

PDF

76.8 KB Created: 2021-03-14 05:58:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c0199c796361b1ee7059fe9cd814d4ed SHA-1: 561486f873b53f331db8004905f4417af632b766 SHA-256: ef638ed8821ee2c2ee37f231670d42caab09f04ff4e82cbe546614c3340b5f4f
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains embedded URLs, one of which points to a suspicious domain ('nipisod.ru'). The ML classifier and ClamAV detection strongly indicate maliciousness, likely related to phishing or malware distribution. The document body, though heavily obfuscated, suggests a lure related to financial formulas, which is a common tactic for scams.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/award?keyword=percentage+base+rate+formula+and+examples+pdf
    • http://varnisvakq.ru/careless_whisper_sheet_music_for_trumpetvwxdh.pdf
    • http://mavitrade.com/62607549443yb698.pdf
    • https://cdn.sqhk.co/remezebona/javaIFj/space_warfare.pdf
    • http://onlajn-kassa.ru/posture_corrector_reviews_consumer_reportsm2iy3.pdf
    • https://cdn.sqhk.co/wavudasawete/jjinHjh/fall_guys_ultimate_knockout_download_apk_android.pdf
    • https://cdn.sqhk.co/mudemodox/ToDge2U/95872163087.pdf
    • https://cdn.sqhk.co/kitatoze/ia4hcfD/83139686274.pdf
    • http://usersdeviceprotectionservice.site/dunodsoxok.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/jolituzoji/all_star_cheer_uniform_shorts.pdf
    • https://uploads.strikinglycdn.com/files/5ac04a17-5958-44ee-936b-738670ed9756/bradley_smoker_heating_element_wattage.pdf
    • https://uploads.strikinglycdn.com/files/db0ad581-a3a8-47a3-bd18-965a92acebb2/preguntas_y_respuestas_del_libro_la_metamorfosis_de_franz_kafka.pdf
    • https://uploads.strikinglycdn.com/files/a41eec74-bbc8-489e-a615-cad30e776676/zagarexudarufugeratus.pdf
    • https://s3.amazonaws.com/ratixifo/mudatem.pdf
    • https://s3.amazonaws.com/xukirizugukugi/how_to_calculate_potential_transformer_ratio.pdf
    • https://uploads.strikinglycdn.com/files/5f3868d0-592b-4c14-8be3-c4fb33f1cb37/hp_laserjet_400_m401n_jam_in_cartridge_area.pdf
    • https://uploads.strikinglycdn.com/files/96d46610-f097-486a-a5f3-78af6cba6ce2/30711627561.pdf
    • https://s3.amazonaws.com/muwomapotumugi/pradhan_mantri_awas_yojana_form_status.pdf
    • https://s3.amazonaws.com/fodose/dulivebobebuz.pdf
    • https://s3.amazonaws.com/dorulusof/fractions_to_percentages_worksheet_gcse.pdf
    • https://s3.amazonaws.com/xomudufe/moment_diagram_uniformly_distributed_load.pdf
    • https://uploads.strikinglycdn.com/files/3ed5716f-6e62-406b-b4b7-a0a4bca53ea0/amazon_wheel_of_time_book_13.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eccd.bin
e6f340148fdc9ad38c46695c8bed89c8746183946883edd0a907888bf7917075
pdf-font-stream PDF embedded font (sfnt) at offset 0xECCD 5684 bytes
font_01_sfnt_off00010012.bin
597214a2e2a138553b45aa5a37edc0e46d11e56c05bd3f1591f639030311804f
pdf-font-stream PDF embedded font (sfnt) at offset 0x10012 11080 bytes