Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1da1188ae8b60c0…

MALICIOUS

PDF

97.3 KB Created: 2021-05-12 10:49:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 78b8513505a12f21327c074d963c9a69 SHA-1: 7048f726049bcf67d3c192b6941bccf4cb6760e0 SHA-256: f1da1188ae8b60c0498ba0336d7c400ba9121907b408d8176b1a29d6f6b93059
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to a suspicious domain, which is a common tactic for phishing or malware distribution. The document body is heavily obfuscated, but the presence of external URIs suggests an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/strik?utm_term=little+prince+cartoon+movie
    • http://sejerodetupumil.medianewsonline.com/great_is_thy_faithfulness_piano_sheet_music.pdf
    • http://wedipum.mygamesonline.org/the_law_of_the_garbage_truck_book.pdf
    • https://cdn.sqhk.co/lokutibu/jajgdOL/best_dirt_rally_game_ps4.pdf
    • https://cdn.sqhk.co/xenudipu/f6ILgcs/zurewuxazivudotimapuf.pdf
    • http://gesetaxoxu.sportsontheweb.net/how_to_reset_samsung_galaxy_s6_back_to_factory_settings.pdf
    • https://cdn.sqhk.co/lokalofobox/fmN9ajh/dodgers_world_series_game_4.pdf
    • http://xisumagogali.getenjoyment.net/international_sales_manager_jobs_in_india.pdf
    • http://joriwolujuf.sportsontheweb.net/19446518428.pdf
    • http://rolorutebu.sportsontheweb.net/3794571952.pdf
    • http://waralolojogeta.sportsontheweb.net/wedding_march_organ.pdf
    • https://cdn.sqhk.co/vugasoveg/e5hsyNL/slots_of_vegas_free_bonus_codes_2020.pdf
    • http://zilitimo.getenjoyment.net/anxiolytic_and_hypnotic_drugs.pdf
    • http://diluzadumavotux.getenjoyment.net/28957862621.pdf
    • https://cdn.sqhk.co/metajewamiva/gcyjeia/bunikeleda.pdf
    • http://waliduv.mypressonline.com/review_skycaddie_lx5.pdf
    • https://cdn.sqhk.co/besudamuge/h9D9Qii/tuzisinumise.pdf
    • https://cdn.sqhk.co/jegivoziba/FZggAih/ccleaner_terbaru_full_version_kuyhaa.pdf
    • https://cdn.sqhk.co/rajunakeb/7HXlgjQ/20504070087.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://nakogis.myartsonline.com/fmea_5th_edition.pdf
    • http://sodowurivav.onlinewebshop.net/advocare_24_day_challenge_journal.pdf
    • http://zijurape.atwebpages.com/canada_express_entry_process_step_by_step.pdf
    • http://todidetiped.onlinewebshop.net/riesgo_cardiovascular_aha.pdf
    • http://japamitafixe.myartsonline.com/quantitative_aptitude_questions_with_answers_in_gujarati.pdf
    • http://positajugopisu.myartsonline.com/menusozogutejasuji.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00013256.bin
b75234c67c90b2ca07e649919d2d6cc5639260b6ab9a743d989ef161ccbaaa3c
pdf-font-stream PDF embedded font (sfnt) at offset 0x13256 3212 bytes
font_01_sfnt_off00013dcd.bin
26613de88099cb2605bff96f545c790b154fffd3133dfde10b13bdb66f382aed
pdf-font-stream PDF embedded font (sfnt) at offset 0x13DCD 4900 bytes
font_02_sfnt_off00014e6d.bin
2a495b9a210acdd58d4fd277fab6eb9658298a1c6d7973dfe8a8bac2940957ef
pdf-font-stream PDF embedded font (sfnt) at offset 0x14E6D 12552 bytes