Malicious PDF — malware analysis report

Static analysis result for SHA-256 f131b2acfcce5bb6…

MALICIOUS

PDF

84.2 KB Created: 2021-03-19 09:57:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eadf8f42b7b19eb45e48a3c00e79aae9 SHA-1: d32808a5ac0ec41986fa1fb130800eec624aabe7 SHA-256: f131b2acfcce5bb69bfa044d7f0fb1d5b6f4c46ce29c0c138731226ecebb4078
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that, when visited, appears to be a search result page. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. The document body, though heavily obfuscated, contains text related to the URL's keyword, suggesting a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/award?keyword=abraham+maslow+hierarchy+of+needs+pdf
    • http://xonibiz.22web.org/tamil_child_rhymes_video_free.pdf
    • http://dexudomidu.22web.org/cable_tray_accessories_catalog.pdf
    • http://mudelukise.iblogger.org/common_sense_trivia_questions_and_answers.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://rapuzezu.epizy.com/gasexoxapumok.pdf
    • https://uploads.strikinglycdn.com/files/4888f83f-6f99-40ad-8ee3-503cc7c4108d/john_deere_175_hydro_attachments.pdf
    • http://jomovexujufadi.epizy.com/63516052975.pdf
    • http://nuzejotegaze.rf.gd/san_diego_citybeat_voter_guide_2018.pdf
    • https://uploads.strikinglycdn.com/files/b047c130-b6af-455a-b0a5-5bddecf4eac6/97307577348.pdf
    • https://s3.amazonaws.com/vogubivajavofu/platform_film_ajay_devgan_ka_platform.pdf
    • https://eadb47d6-6712-4ecd-aa5a-2cdcf2d90b86.filesusr.com/ugd/c844bf_2c95e6fc2e8b4828a7e7a7e4e9fe3ffe.pdf?index=true
    • http://danidarexixuw.epizy.com/witonebogenidosojuv.pdf
    • http://welurolakis.epizy.com/carpophilus_hemipterus.pdf
    • http://zusobudem.epizy.com/78482880948.pdf
    • http://jawuguv.epizy.com/75_common_interview_questions_and_answers.pdf
    • https://s3.amazonaws.com/zarelusipofox/due_diligence_review_template.pdf
    • https://s3.amazonaws.com/zolerazowubow/kusowagej.pdf
    • https://s3.amazonaws.com/fogibi/50015903580.pdf
    • http://fibobaxemod.rf.gd/51988859670.pdf
    • http://dojukedak.epizy.com/jiwonugibategizejo.pdf
    • https://uploads.strikinglycdn.com/files/75a5001b-575d-4af5-ba46-99878d26edfe/vokixotinolexufakudebepur.pdf
    • https://254b3b0b-79dc-4992-827c-fd4bb3db3178.filesusr.com/ugd/f515ca_e85ad2dfb6254875b4715fafb569c64c.pdf?index=true
    • https://s3.amazonaws.com/fuwenoxuzasila/40501398306.pdf
    • https://7be326e9-a1fd-4761-a84c-83c904220737.filesusr.com/ugd/37e945_0cb2552d254942ff8167a1fbaea8f311.pdf?index=true
    • https://c01188fd-d8af-4b86-846b-090f7ecd58d8.filesusr.com/ugd/9058e5_230846e9c33042db9294c4bdaf506e79.pdf?index=true
    • https://uploads.strikinglycdn.com/files/64c72269-f6f4-4fcc-a20f-6a3e2f3bf193/35408001197.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f50b.bin
07c009fe3420155871dab6a5444e6c5af6dbb5321d5313a107242b8ffa45934d
pdf-font-stream PDF embedded font (sfnt) at offset 0xF50B 5428 bytes
font_01_sfnt_off00010759.bin
5483ef67b1b514796f06f09a2dfbbff7fc1abf9e04553d2a7bba39661fd42242
pdf-font-stream PDF embedded font (sfnt) at offset 0x10759 13932 bytes
font_02_sfnt_off0001335b.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x1335B 4324 bytes