Malicious PDF — malware analysis report

Static analysis result for SHA-256 ffebf6f76d6760a4…

MALICIOUS

PDF

75.6 KB Created: 2021-05-23 09:49:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 82a902aefbbf16385b82d8834461a23b SHA-1: ecd5194d4b5ce17fff776eba06fdbf47328ba777 SHA-256: ffebf6f76d6760a4262de6c269264d2b5954a5165fad889da11f2a28417af527
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF document that contains an embedded URL pointing to a phishing site. The document body, though heavily obfuscated, suggests a lure related to a 'death certificate application form'. The presence of the PDF_URI heuristic and the ML_NYX_PDF_MALICIOUS classification strongly indicate malicious intent. The primary IOC is the external URL, which is likely used to host the phishing content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=death+certificate+application+form+pdf+odisha
    • https://static.s123-cdn-static.com/uploads/4484103/normal_5fce68c9b388d.pdf
    • https://static.s123-cdn-static.com/uploads/4367294/normal_5ff6a93baedae.pdf
    • https://static.s123-cdn-static.com/uploads/4406777/normal_5ff880e34a563.pdf
    • https://cdn-cms.f-static.net/uploads/4482402/normal_601368368b25c.pdf
    • https://cdn-cms.f-static.net/uploads/4479451/normal_60638fd58f984.pdf
    • https://cdn-cms.f-static.net/uploads/4446382/normal_605652b258a36.pdf
    • https://cdn-cms.f-static.net/uploads/4473388/normal_604f79a31ade0.pdf
    • https://cdn-cms.f-static.net/uploads/4389576/normal_603a227c976cd.pdf
    • https://static.s123-cdn-static.com/uploads/4479439/normal_5fc75364736bc.pdf
    • https://cdn-cms.f-static.net/uploads/4418981/normal_603c7fc14db2a.pdf
    • https://cdn-cms.f-static.net/uploads/4389792/normal_60661cf247037.pdf
    • https://cdn-cms.f-static.net/uploads/4405903/normal_602b41d4a1253.pdf
    • https://cdn-cms.f-static.net/uploads/4387240/normal_602e4079e9437.pdf
    • https://static.s123-cdn-static.com/uploads/4474446/normal_5fe043c261343.pdf
    • https://cdn-cms.f-static.net/uploads/4445125/normal_603ac5bec5749.pdf
    • https://static.s123-cdn-static.com/uploads/4389127/normal_5ffd3ed40c437.pdf
    • https://static.s123-cdn-static.com/uploads/4407782/normal_6007337f719a8.pdf
    • https://static.s123-cdn-static.com/uploads/4485946/normal_5fcfe677cc733.pdf
    • https://cdn-cms.f-static.net/uploads/4408589/normal_606995dae732e.pdf
    • https://static.s123-cdn-static.com/uploads/4453329/normal_5ff686a751e3c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vofadoloves/om_3d_video_songs_free.pdf
    • https://s3.amazonaws.com/gozilum/how_to_turn_up_volume_on_symbol_scanner.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eada.bin
80671eb9e54f6bed7fd99203a21906dee7b673763ab9043cffd4f714d9eee195
pdf-font-stream PDF embedded font (sfnt) at offset 0xEADA 5396 bytes
font_01_sfnt_off0000fd0e.bin
ddc42fbb2cd1e219795161d9e565ac2cc4639678cca287e27f4bb80fbea62122
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD0E 10568 bytes