Malicious PDF — malware analysis report

Static analysis result for SHA-256 f88a80da971f62e1…

MALICIOUS

PDF

467.1 KB Created: 2021-03-21 07:07:38 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-13
MD5: 23b42c1a1c9f0cf4e1429ef3dc45eac6 SHA-1: 85f3ffc9f647ba4a8cf3180fd8676b89367e606c SHA-256: f88a80da971f62e12ab582d6dee82e8479a32a9efe3743244e8907f0f73f7848
66 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URI pointing to a suspicious domain, identified by ClamAV as a phishing trojan. The document body, though heavily obfuscated, appears to be related to a book title, likely serving as a lure to encourage clicks on the malicious URL. No scripts were extracted, but the presence of the external URI and the ClamAV detection strongly suggest a phishing attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.0642

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=la+casa+de+bernarda+alba+pdf+cervantes+virtual PDF link annotation
    • https://cdn.sqhk.co/nokowifupe/VHBfjgF/zonifatutet.pdfIn PDF document text
    • https://cdn.sqhk.co/mapuvokunoj/HD7ihjc/28638906739.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4426701/normal_602b61536b3fc.pdfIn PDF document text
    • https://cdn.sqhk.co/salusasopuvi/jhgdEib/music_landing_page.pdfIn PDF document text
    • https://cdn.sqhk.co/lekuruzomef/hj3wbnL/25th_amendment_in_constitution_of_pakistan.pdfIn PDF document text
    • https://cdn.sqhk.co/narulaloro/eihH0L7/weapon_masters_roguelike_mod_apk.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4460460/normal_5fe61f39cbfc2.pdfIn PDF document text
    • https://cdn.sqhk.co/muditazu/chdijgc/34403486058.pdfIn PDF document text
    • https://cdn.sqhk.co/luwesefizi/hgshhfJ/pool_service_professionals_llc.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4376874/normal_5ff1fc5dcc5c8.pdfIn PDF document text
    • http://fontawesome.iohttp://fontawesome.io/license/In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://scripts.sil.orgThisIn PDF document text
    • http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
    • http://smc.org.inhttp://smc.org.inIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.indictrans.orgIn PDF document text
    • http://www.fontrix.comhttp://www.nhncorp.comIn PDF document text
    • https://s3.amazonaws.com/muvarelo/understanding_business_11th_edition_ebook.pdfIn PDF document text
    • https://d1159ab4-cbf5-42eb-897b-83a5e94cd7da.filesusr.com/ugd/536122_85bb143d17e34bcfa388b52af14113f9.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/sinadi/95650230985.pdfIn PDF document text
    • https://a6668164-4238-4e0d-addb-cc4c62f58fca.filesusr.com/ugd/2dfcca_2f8f3674883247109057a1f4131d8d3f.pdf?index=trueIn PDF document text
    • http://bazolajeruda.rf.gd/ncis_new_orleans_the_river_styx_part_ii_cast.pdfIn PDF document text
    • https://37bdae34-bb2f-403f-997c-54a7c09d9c06.filesusr.com/ugd/dc98cc_e485a90da3934285aa052837da8b08db.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/kovozenamofox/bekapakebopedonaruluxezer.pdfIn PDF document text
    • http://zanebinelit.rf.gd/asymptotic_form_of_airy_function.pdfIn PDF document text
    • http://posidepixofonep.epizy.com/a2_reading_comprehension_practice_test.pdfIn PDF document text
    • https://s3.amazonaws.com/ruzumeb/android_handler._callback_handlemessage_return_value.pdfIn PDF document text
    • https://7ef5d8b8-74ac-4e0a-b0a0-fa61ca6462a8.filesusr.com/ugd/23e9be_87ec8a1d06b8410c90b05a4761e1c819.pdf?index=trueIn PDF document text
    • https://025b4bf0-2906-4f5f-8a0f-6d4b68fc9518.filesusr.com/ugd/148ee2_9cb55c726cbc42b3a03e768bc7ded009.pdf?index=trueIn PDF document text
    • http://nanebovovut.epizy.com/pattern_recognition_and_machine_learning_christopher_bishop_download.pdfIn PDF document text
    • https://s3.amazonaws.com/mupukesunobaga/54363387821.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://scripts.sil.org/In PDF document text
    • http://scripts.sil.org/OFLAbyssinicaIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlTibetanIn PDF document text
    +2 more URL(s)

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_014_off0006c0f8.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6C0F8 36748 bytes
SHA-256: 1bd90e5846021ffd17d668f218460c4acb9172d07250051f3b025e094e5cf416
font_00_sfnt_off0004ba2e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4BA2E 11560 bytes
SHA-256: 34c2bca5824800ae193ce192efe6cf471d2e5db29a6e4d81fe896277fde81cfb
font_01_sfnt_off0004d6ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4D6AE 46848 bytes
SHA-256: 37fd932675d4a6475d231db7f7ba79754ff5acf3372dffe703cfdf8322c30af9
font_02_sfnt_off0005653d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5653D 1668 bytes
SHA-256: 6c4b6e19481b0ed761bdd7505e6888df93f015d24599fd403a2c77e9c178275c
font_03_sfnt_off00056d8b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x56D8B 5292 bytes
SHA-256: 49d29a6cf7d60e2aa9f327bfbefaae9e8a62541371e2a977310ddfd89660062b
font_04_sfnt_off00057f59.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x57F59 6580 bytes
SHA-256: 75c403a8d504a0acc9173a515bad6cbc2feda3052f7b3331721712b4588c810c
font_05_sfnt_off00058f9d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x58F9D 22456 bytes
SHA-256: 8fce711fedb68aba2ffcda2badc6687891184225d87f43cca99e4f3e0f42e9b1
font_06_sfnt_off0005b3bb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5B3BB 8688 bytes
SHA-256: 6f19fb84c80eebc9206ffa3233f5e12a0c1aaef7f5d39160ecb7f9db5bd083ec
font_07_sfnt_off0005c4b0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5C4B0 2564 bytes
SHA-256: 2dcd36784a6f37059b270d207b2728a9745b438d9ae1811e259b3f3a4d841862
font_08_sfnt_off0005cecd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5CECD 2864 bytes
SHA-256: 6e7388f29f1d7ddc4d11b648e89d324b07653f52d4da819c090a6f95a96a6568
font_09_sfnt_off0005daee.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5DAEE 6532 bytes
SHA-256: 4e6325fd0c988876b2a064c0ea432e4333c27965154c7a6bd965791b0cf84283
font_10_sfnt_off0005ead5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5EAD5 3772 bytes
SHA-256: 56a027e0c136a199c331c60ff32fcc2e4a29ad24f8fc85650d87563801a95641
font_11_sfnt_off0005f665.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5F665 77908 bytes
SHA-256: 863ab25022ee73149e45e6960210cac566c1a8c855bb186d26c0a0481d4eadf1
font_13_sfnt_off00070f70.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x70F70 2708 bytes
SHA-256: c84f8acab3a9c5ca2adc69b236825ca6c9665d498d6e40b336d2bb841533e12c
font_14_sfnt_off00071a8c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x71A8C 10320 bytes
SHA-256: 97c8512466c6b874587be1a5d547db8b96786ac10c100d380b8fad136fef1175