Malicious PDF — malware analysis report

Static analysis result for SHA-256 0248e4830a5ec2b6…

MALICIOUS

PDF

71.2 KB Created: 2021-03-05 09:43:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 45eba7cbdd2fd10ce0ea5eec5eba0c43 SHA-1: 933ce53abe98d9bc762a99baeda92f4e9086a6bf SHA-256: 0248e4830a5ec2b649b54424d01e7f5017d4189a9a2333af62cabd824962d4b9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, suggesting a link farm designed to redirect users to various malicious or SEO-spam websites. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic strongly support this attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/wix?keyword=tame+impala+pomona+stubhub
    • https://cdn.sqhk.co/noperizapewo/ijdhjIi/gitopilepawobotitupuliza.pdf
    • https://cdn.sqhk.co/toromerepowa/7gchjhi/crystal_blast_elite.pdf
    • http://punavuvipufov.sportsontheweb.net/nenepoxejepadukekezedo.pdf
    • https://cdn.sqhk.co/zepipawetopi/iiewmhf/21946125931.pdf
    • https://static.s123-cdn-static.com/uploads/4403948/normal_6003b26649b5c.pdf
    • http://polobasopika.mywebcommunity.org/54980477722.pdf
    • https://cdn.sqhk.co/dezosanag/Srifge2/joresilojapobevura.pdf
    • https://cdn-cms.f-static.net/uploads/4428341/normal_602d550e2d687.pdf
    • https://cdn.sqhk.co/mudinaxape/Iw7ljiC/8723855983.pdf
    • https://cdn.sqhk.co/pelotuwew/gjaoicN/dubakuxive.pdf
    • https://cdn.sqhk.co/wakewafo/jhgjs7D/plants_vs_zombies_2_online_hacked.pdf
    • https://cdn.sqhk.co/xevuvuxene/aAmXidQ/best_strawberry_ice_cream_recipe_serious_eats.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://0cfe495c-9a5f-46a1-a5f3-fb21b6211bac.filesusr.com/ugd/7aabb2_038055b587dd4702a2220ede692b1d59.pdf?index=true
    • https://492f55f4-3442-4b37-b17e-39d9f2f0ae8a.filesusr.com/ugd/7dfe85_ef61e787d49746f6b30dea861a7b5488.pdf?index=true
    • https://c301b42c-deab-4116-afcd-a09dd0728425.filesusr.com/ugd/4bb894_63fe0fbaa8e94161ba81fc2d39fe12aa.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b200ebf7-2372-4df0-ae99-2e5b78dbbb49/83636526152.pdf
    • https://uploads.strikinglycdn.com/files/327b8421-03c6-4d82-9fcb-1f46895a04a4/puma_silent_oil_free_air_compressors.pdf
    • https://f495c71d-628d-4070-9a3d-b699cbb46ba4.filesusr.com/ugd/d99ef3_fb013d71b7ca4e8b870f759d6475555b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/05e57e76-2e0c-4836-9a26-3c4ae3a38819/vw_transmission_fluid_change_tool.pdf
    • https://uploads.strikinglycdn.com/files/3a7373f4-1e2c-4fc3-b497-4b1369c15e31/the_miracle_morning_nighttime_affirmations.pdf
    • https://27a83426-c768-4525-a63d-b5b732cca755.filesusr.com/ugd/28b3f7_f0e782d25f094504a7fc6ecbe7ea6024.pdf?index=true
    • https://uploads.strikinglycdn.com/files/962d50e6-7d0a-4cfe-85a9-0a58dd618003/56752869308.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da65.bin
ac5e2d8e952c10997bc4393673f82fd59d94163c320a453cab1ba50ac853a515
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA65 5052 bytes
font_01_sfnt_off0000eb64.bin
a4e43fc0b00760beb3449bdd19b226b2074efc6603009168030d62821a1dd92c
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB64 10624 bytes