Malicious PDF — malware analysis report

Static analysis result for SHA-256 fafebd4e714cde5c…

MALICIOUS

PDF

200.6 KB Created: 2021-04-13 22:57:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bff621bd968c308d0fefd2ae5826e6a3 SHA-1: b587d2291e0f4c1aa50dbde8c6cfa52e3fce2432 SHA-256: fafebd4e714cde5c6be7adf888fd0ca2fe12dc2703191a9b4f88821db1ea57de
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a suspicious domain. ClamAV and ML classifiers have identified this file as malicious, specifically a phishing trojan. The presence of the external URI and the ML detection strongly suggest a phishing attempt designed to redirect users to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=what+is+fire+biblically
    • https://static.s123-cdn-static.com/uploads/4392453/normal_5ff455962b24f.pdf
    • http://sis-paypal.com/13231162870rzx3i.pdf
    • http://triple-doska4.club/memigambpic.pdf
    • http://lijovafe.22web.org/polysemy_synonymy_hyponymy_and_antonymy.pdf
    • https://xediziku.weebly.com/uploads/1/3/1/3/131384396/kalepida-karejazumo.pdf
    • http://zavarivaemvmeste.ru/zisepirunupekamitezasibegpt3i.pdf
    • https://cdn-cms.f-static.net/uploads/4424982/normal_604948244c3c0.pdf
    • http://naturka.space/electrophilic_addition_reaction_worksheeta7p2e.pdf
    • https://nonejekorozu.weebly.com/uploads/1/3/4/1/134108542/viruzuxidusuk.pdf
    • http://bagesopabiwub.scienceontheweb.net/agaricus_bisporus.pdf
    • http://zomosidotewe.sportsontheweb.net/20381567615.pdf
    • http://lazirawolewok.getenjoyment.net/how_do_i_program_my_directv_remote_to_work_my_tv.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/votubukaxogilix/basivexefevidezuvuvurezo.pdf
    • http://zufonokimilije.epizy.com/govugegujexes.pdf
    • https://s3.amazonaws.com/tirimofufemukat/segukagina.pdf
    • http://jeduzoli.rf.gd/fiwamirazuzofo.pdf
    • http://puwapogajamafar.epizy.com/napaxifiwexetivolunudel.pdf
    • http://nununad.myartsonline.com/automatic_control_engineering_5th_edition_raven.pdf
    • http://sufafawujufex.epizy.com/everything_about_periodic_table.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002dad3.bin
630ccdf5373638d22bee083465f9670ed81ecba75480500b06539416f4fd573a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DAD3 5224 bytes
font_01_sfnt_off0002ecaa.bin
dfb00c7f7481fc876c1ed9f2b836b7a92154f15854920f77ebb515f8825a0a95
pdf-font-stream PDF embedded font (sfnt) at offset 0x2ECAA 11048 bytes