Malicious PDF — malware analysis report

Static analysis result for SHA-256 f24978d5bc0e4b72…

MALICIOUS

PDF

73.3 KB Created: 2021-03-16 10:42:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: 0d7407505294d79cc5764c51ff86ac51 SHA-1: 1f6f136c20cce7d0f0ffe65b75132f539f8eb913 SHA-256: f24978d5bc0e4b724d237353777101473a7ae8d2ad50a00dc1ef41eea98dc8df
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as a malicious PDF by ClamAV and an ML classifier. It contains an embedded URI pointing to 'soxebez.ru', which is likely used for phishing or to download a secondary payload. The PDF structure and embedded content suggest an attempt to deceive the user into interacting with the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/award?keyword=business+analysis+courses+for+beginners+pdf PDF link annotation
    • http://siankaanmexico.com/15779892000ytgst.pdfIn PDF document text
    • http://openlait.pro/doctor_faustus_act_3_scene_1_summary8llr8.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4419832/normal_5fc8660029110.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4456134/normal_5fd05a3887058.pdfIn PDF document text
    • https://cdn.sqhk.co/vorebilifi/lYgd1op/82125963411.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4464534/normal_5ff43a9947383.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4418001/normal_603bf5df7845c.pdfIn PDF document text
    • http://balifruit.com/70958025180axmmu.pdfIn PDF document text
    • https://cdn.sqhk.co/nosuterib/hbUibhi/rayan_hamrah_ios.pdfIn PDF document text
    • https://cdn.sqhk.co/ramidazumiko/jfhg6gc/72384424292.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4387031/normal_5fe0bb822a4d6.pdfIn PDF document text
    • http://betmoy54.com/86933049664z1clu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_6c832654b74d43f292eb15bd744d7cff.pdf?index=trueIn PDF document text
    • http://notijopozij.epizy.com/movie_box_app_apk_file.pdfIn PDF document text
    • https://s3.amazonaws.com/jinabisura/nenizipu.pdfIn PDF document text
    • https://s3.amazonaws.com/dorulusof/97761384075.pdfIn PDF document text
    • https://bc881323-2374-4635-a2b7-f126f9929bd8.filesusr.com/ugd/546a35_8a5864d60eb04cf6a6ece05ca779b580.pdf?index=trueIn PDF document text
    • http://lakiver.epizy.com/62579286868.pdfIn PDF document text
    • https://s3.amazonaws.com/zifilobesumafi/11429898963.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e0f0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE0F0 5612 bytes
SHA-256: 6990c297394d79401ef957085da8e8aa0570f442d399c46f8bba710168926b11
font_01_sfnt_off0000f41f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF41F 9972 bytes
SHA-256: 854f421447f0d50e38196cf7fd069728ea9e3204f753c3539ded94c66f470e05