Malicious PDF — malware analysis report

Static analysis result for SHA-256 f0e3121b64cb638b…

MALICIOUS

PDF

83.8 KB Created: 2021-05-07 20:34:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4fd234619133c4254ae05f6740087ce5 SHA-1: 01fbe0f94b7ef0d0769df5aa9a20ff6af32605ac SHA-256: f0e3121b64cb638b88158be83efe422e09901b201a50d797288493b60b81dddd
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains an embedded URI pointing to a suspicious domain, and ClamAV detected it as a phishing trojan. The ML classifier also flagged it with high confidence. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect the user to a malicious site, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9970

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=it%2527s+kind+of+a+funny+story+do+you+like+music
    • http://itdiscount.pro/zudabr9pqu.pdf
    • https://welomutulek.weebly.com/uploads/1/3/4/8/134873792/3864729.pdf
    • https://cdn-cms.f-static.net/uploads/4484399/normal_602e37b697d83.pdf
    • http://mebets.xyz/peg_perego_john_deere_ground_force_tractor_with_trailer_for_sale4b5jv.pdf
    • https://cdn-cms.f-static.net/uploads/4494146/normal_606a1c0b61c37.pdf
    • https://cdn-cms.f-static.net/uploads/4414342/normal_60492f9a578bd.pdf
    • https://static.s123-cdn-static.com/uploads/4454301/normal_600223b591cb4.pdf
    • https://kenaveduku.weebly.com/uploads/1/3/0/8/130813649/segule.pdf
    • http://xezifimo.iblogger.org/18930804485.pdf
    • https://kelebididoxo.weebly.com/uploads/1/3/2/6/132681806/lavobudajen.pdf
    • https://cdn-cms.f-static.net/uploads/4465151/normal_6016435d99bc5.pdf
    • https://cdn-cms.f-static.net/uploads/4454422/normal_601fa81559d11.pdf
    • http://sport-stavki.fun/does_hs_mini_maxx_have_lope_tunekzm62.pdf
    • https://static.s123-cdn-static.com/uploads/4408184/normal_5ff8af4c9e1bb.pdf
    • http://pixelbarista.com/538299506074inti.pdf
    • https://static.s123-cdn-static.com/uploads/4383132/normal_5fe5de5811c15.pdf
    • http://zoxatib.iblogger.org/fedunixewofag.pdf
    • https://cdn-cms.f-static.net/uploads/4474985/normal_5fdc37ef0cbf6.pdf
    • http://bridgecommerce.com/anatomy_of_nose_and_paranasal_sinuses7p9ak.pdf
    • https://xutorobufazam.weebly.com/uploads/1/3/5/3/135345650/4ba8ca2112ef5.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://wanodabife.rf.gd/foxazaworotor.pdf
    • http://wuzisop.epizy.com/baby_bonnet_sewing_pattern.pdf
    • http://pugilem.epizy.com/cash_flow_management_tools.pdf
    • http://tawexega.epizy.com/gekojasibidonozox.pdf
    • http://vejobewibibir.epizy.com/faredorominusajenuvaw.pdf
    • http://pobediwawe.epizy.com/google_play_store_apk_for_android_tv.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001042a.bin
11d1159f66d634e03e029bb345981e508615d11edbb9a749b8f4a9f6227c63b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1042A 5304 bytes
font_01_sfnt_off00011631.bin
54fdd5e426e87ab86c746363453909c1ab4caa9e4fabd957244303686df089b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x11631 12300 bytes