Malicious PDF — malware analysis report

Static analysis result for SHA-256 f94c692ae95fe170…

MALICIOUS

PDF

175.6 KB Created: 2021-04-01 19:27:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-10
MD5: 39718f597f28ec0f95a229f243c31a45 SHA-1: f5339f5a67304c8eb53d45cd74730a4e8d8b26f8 SHA-256: f94c692ae95fe170c7d1a9cabcaf2faef8cba91485fa3ac41967cf571d23dff9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains an embedded URL that redirects to a phishing site, disguised as a search result. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the phishing lure suggest an attempt to download further malicious content or redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8527

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/award?keyword=agile+methodology+steps+pdf PDF link annotation
    • https://cdn.sqhk.co/dusujukakal/EDDhfii/19228882821.pdfIn PDF document text
    • https://cdn.sqhk.co/libavesonon/bQdqaAJ/cool_math_games_moto_x3m.pdfIn PDF document text
    • https://cdn.sqhk.co/duxadikoti/egijjuA/48356754986.pdfIn PDF document text
    • https://cdn.sqhk.co/zojixemem/Jieggih/bullet_echo_hack_iosgods.pdfIn PDF document text
    • https://xufipenisugiw.weebly.com/uploads/1/3/0/8/130873979/3572996.pdfIn PDF document text
    • https://kajumosezu.weebly.com/uploads/1/3/4/7/134749214/kuxejeke.pdfIn PDF document text
    • https://duzigavejad.weebly.com/uploads/1/3/4/5/134513143/5519221.pdfIn PDF document text
    • https://cdn.sqhk.co/widiroje/heMhiib/validity_fingerprint_sensor_driver_setup.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • https://uploads.strikinglycdn.com/files/c781d3e1-6070-4ff8-8daa-c19ebf016a4f/36221638802.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c78b71ad-22b2-4f33-9e26-e6f47691dad5/what_alice_forgot_movie_imdb.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fb2dffcc-a112-4d84-8e46-467b4507531f/how_to_become_a_exotic_animal_specialist.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/90840cea-1b24-4020-bec5-b45e840c2b39/zofadazepikix.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e2f10fc8-fdf0-4987-9589-a9c4e3b5f9fe/keketejozarifibogotiv.pdfIn PDF document text
    • https://s3.amazonaws.com/banula/what_are_the_best_classical_guitar_strings.pdfIn PDF document text
    • https://s3.amazonaws.com/jivagajamav/57554861226.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHongIn PDF document text
    • http://www.geocities.com/dnhhngIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://scripts.sil.orgIn PDF document text

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_012_off00026695.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x26695 18200 bytes
SHA-256: a0961b42c5318ff6115bd86d58da556a695fb66bbea1a70eb3ab397eb474bd09
font_00_sfnt_off0001c031.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C031 5684 bytes
SHA-256: 8dd08da0b50e983952fe00ff37b6d1e9ad3cc266fe914d8be907ccb254108774
font_01_sfnt_off0001d405.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D405 5240 bytes
SHA-256: a8f1062b4809fa42b56847f5dd4bdf24a7d3e1bbba7d0a8815954935915dc525
font_02_sfnt_off0001e5c6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1E5C6 2656 bytes
SHA-256: c206ac4eca120f096112d408dff6b33a2f721090936d80486df636e1cd240fde
font_03_sfnt_off0001f0c6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F0C6 4544 bytes
SHA-256: 8de763cc392d555d6555ce28e49a7801ce7361977d5c0c1f0cca23967a7df2d1
font_04_sfnt_off0001fed0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1FED0 2604 bytes
SHA-256: 7f3a1ef136f36ba68bc36e5bcd31de243dce7f4b60e01c4bc40f508baeb48ca0
font_05_sfnt_off000209ab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x209AB 3840 bytes
SHA-256: cca5298ad2e89ab0d41cc63a8205340d9321530172a8d5dda1c28d17fa56adaa
font_06_sfnt_off000217b8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x217B8 2108 bytes
SHA-256: e66bd646ff29f48b94a898642357a1d5295b77faffa0bd70eb77acb4aebc9a97
font_07_sfnt_off00022184.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22184 6640 bytes
SHA-256: eca62b72654736461a635ba366d09d794777fd95c58152d2b251becdfce657e0
font_08_sfnt_off00023322.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23322 17344 bytes
SHA-256: c7faaa2396427e8156cf99cbc02151a9da20ae74ef9e05b67831e05bd877a7f2
font_10_sfnt_off00028396.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x28396 3848 bytes
SHA-256: ddc549338fcc81ec40a7b4a692679fe8edf12a605c6e06bbb20a40a2c05f504b
font_11_sfnt_off0002926d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2926D 4356 bytes
SHA-256: de8bdd4d27b85fe5e1825bdf30309bd3fb6e4ce3935015bd39a0f1293a5d4eff
font_12_sfnt_off0002a0dd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2A0DD 2608 bytes
SHA-256: c4869f4910101e9de114603d80c87e7465cc14a3edf423f39a6ef78b10429b6f