Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe3d0677d12a717f…

MALICIOUS

PDF

89.0 KB Created: 2021-03-14 05:26:59 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1e94dfe3f425eb2677e9d3ae4413e384 SHA-1: 6aff49ed693af6effb25a7ecc3c85a1538b843fa SHA-256: fe3d0677d12a717f3ce12dad30777555326447e817dd69bc382dd0688378534e
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains numerous embedded URLs, with the primary one being https://druttle.ru/wix?keyword=effects+of+storms+article, suggesting a lure to a malicious site. The document body, though heavily obfuscated, contains metadata related to its creation, indicating it was likely generated by wkhtmltopdf, a tool sometimes used to create malicious PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=effects+of+storms+article
    • http://alisaborodaenko.design/portugal_the_man_woodstock_albumrcc04.pdf
    • http://idslim-italia.site/73598008352tnkg5.pdf
    • http://ekzo-fruit.ru/47456579122oe19b.pdf
    • http://sixesijilolun.mywebcommunity.org/30221448541.pdf
    • http://bcpzon4segurabetaviabcp.com/integral_calculus_inverse_trigonometric_functions_sample_problemsou6r3.pdf
    • http://foxiduwanati.mygamesonline.org/netgear_wnr2000_setup_as_switch.pdf
    • http://healsmall.space/28762246513vn450.pdf
    • http://taptopbot.com/jeepers_creepers_1_full_movie_downloadg1ejx.pdf
    • http://pegijegur.mygamesonline.org/foruzilarapidusaxeked.pdf
    • http://iminn.ru/rosukukot9wi7.pdf
    • http://alcozerox.com/rhapsody_in_blue_orchestra_score1k782.pdf
    • http://raftgjgr.space/convert_cfg_into_chomsky_normal_formop701.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zavozolumox.rf.gd/biogenic_amines.pdf
    • https://4db61c00-1078-4917-8a1c-a2c1480eb6e0.filesusr.com/ugd/c94206_0705ce1c283f4264a37f14dc50eb331e.pdf?index=true
    • https://9480ebe7-8096-4165-94d5-b35dd525e9f4.filesusr.com/ugd/07b43d_d7a7db50e892411a984261be8eee4aa9.pdf?index=true
    • http://fawosafo.epizy.com/opentx_companion_manual.pdf
    • https://s3.amazonaws.com/panalipolifod/nazar_battu_hd_video_song.pdf
    • https://s3.amazonaws.com/xixonu/pyar_badmash_song_pagalworld.pdf
    • http://jujiruwer.rf.gd/director_of_field_service_job_description.pdf
    • https://1a6defe7-92a0-4357-8a70-d3bce85d30c9.filesusr.com/ugd/385065_8ad0afecbef64922920b24ad401c5919.pdf?index=true
    • http://zubafazebet.epizy.com/xudaxumuzewuzomigojotulux.pdf
    • http://nofugodevi.rf.gd/21014052904.pdf
    • https://92923600-264c-4cb8-9d87-181083d4f0d6.filesusr.com/ugd/0bf43f_3b34fa7485e748fba0fda50c53ff10a2.pdf?index=true
    • https://f05e0dbb-21cf-40ea-8b71-00b8d6f49a3b.filesusr.com/ugd/b09e1d_5df7b84898b84c8b92664dd75b725e6d.pdf?index=true
    • https://s3.amazonaws.com/pajukovuxetu/80215408054.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011dbc.bin
a509c2e1c4e2084027abe53e9891a5f48e52a606f7f6ea07784441c2ee66b9b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x11DBC 4984 bytes
font_01_sfnt_off00012e9c.bin
bc31a21a96007209134fddfb75412db3d3da2aee28c66edf459da9fca6bb2cb2
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E9C 11896 bytes