Malicious PDF — malware analysis report

Static analysis result for SHA-256 f09ab9832ef07151…

MALICIOUS

PDF

103.5 KB Created: 2021-03-29 20:21:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 31ab3601e885d084dc61cc7592c1e65a SHA-1: d925941408b6fc4c3158980bb11e20a260de2646 SHA-256: f09ab9832ef07151a31cf00a8a2b0ead243fd96ed59bca0e6101e5b263fd38b9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains embedded URLs, one of which is flagged as suspicious. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of embedded URLs suggests an attempt to redirect the user to a malicious site, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=hdmi+link+assurance+input+lag
    • http://xebupado.mypressonline.com/antinomias_juridicas.pdf
    • http://cparta.moscow/worizokabesemamupotitusggn.pdf
    • http://capridigi.com/free_first_grade_english_worksheetsuu56m.pdf
    • http://cashfree.store/mercruiser_5.0_oil_filtersjgng.pdf
    • http://creamwalls.space/shot_clock_violation_adalah8trtw.pdf
    • http://bokaxakoz.sportsontheweb.net/geometric_figures_engineering_drawing.pdf
    • http://solapp.xyz/928077245618rg8p.pdf
    • http://copyrighthelpptteam.com/lutupibesetegukanuxugomextxhnu.pdf
    • http://vixabaj.scienceontheweb.net/phonetics_transcription_exercises_with_answers.pdf
    • http://kvrovk.xyz/20392260136epymh.pdf
    • http://keniworu.mywebcommunity.org/idioptico_definicion_medica.pdf
    • http://nelolizavulejuj.medianewsonline.com/levigi.pdf
    • http://daating19.site/jevelemol14bv.pdf
    • http://yyyyyyhhhhh.space/pamevomudoxexudedozukispd0x.pdf
    • http://priz24.site/bidovumidemiriwexugavovig05gm7.pdf
    • http://axecheat8.xyz/fojimesitodogisifisvkp1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://8035c368-62b5-4e0f-b07c-73fd2baf85c9.filesusr.com/ugd/2ee8d4_1ff69555f7e44389ba1307a84cb89c8e.pdf?index=true
    • https://041aa876-b65b-432c-96c0-58c8b295a4e4.filesusr.com/ugd/90d19e_1645776bbced4a118efd43cf263beb41.pdf?index=true
    • https://s3.amazonaws.com/gopuze/forme_allocutive_inglese.pdf
    • https://s3.amazonaws.com/pojikovewijeja/alesis_q25_midi_keyboard.pdf
    • https://s3.amazonaws.com/pirofopafu/degogugojemanibud.pdf
    • https://s3.amazonaws.com/mubemutolewe/sekelefafitu.pdf
    • https://af0fe010-594a-4ec7-a26b-e2d78e33490d.filesusr.com/ugd/7d2910_cd28c1857fce46ac9ee691a13fe54b96.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015411.bin
73dd8501aa6e39618323351527443ff4a9360fcb6e9381807c655be0bdebdb45
pdf-font-stream PDF embedded font (sfnt) at offset 0x15411 5420 bytes
font_01_sfnt_off00016661.bin
0cb7f8e6c0a3f89317bc7634c02b456fe046f44046aff393f0361941fa4fe0c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x16661 12528 bytes