Malicious PDF — malware analysis report

Static analysis result for SHA-256 02ebad3f275c35eb…

MALICIOUS

PDF

96.0 KB Created: 2021-03-16 07:50:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e1a1331c99e48570c362387e622f1530 SHA-1: 9b8377c477b13f55904d803ff648c997904e76de SHA-256: 02ebad3f275c35ebd2e6fc86866947b14c49cac3d6a1d347d75277b4100f8a09
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of external links, many of which point to other PDF files, indicating a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. The document body, though heavily corrupted, contains keywords related to the embedded URLs, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9946

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/wix?keyword=gm+window+regulator+guides
    • http://javaxirivibewi.mygamesonline.org/gesunesazate.pdf
    • http://mjawebdesign.net/muvowo0tpz5.pdf
    • http://sewonmedix.ru/tulozedug6s5dj.pdf
    • https://cdn.sqhk.co/gonuromabime/cPEigja/frases_tumblr_sad_girl.pdf
    • https://nobewiga.weebly.com/uploads/1/3/5/3/135315034/5754017.pdf
    • http://dimozakebaba.scienceontheweb.net/photosynthesis_in_bacteria.pdf
    • https://cdn.sqhk.co/pogadidotilu/AhhN8ie/rotator_cuff_injury_treatment.pdf
    • https://gelejidog.weebly.com/uploads/1/3/4/6/134688201/fakanafuk.pdf
    • https://padawevuwelidas.weebly.com/uploads/1/3/1/4/131438111/2916ee8d508f3.pdf
    • http://pogekoxuw.mygamesonline.org/segisonako.pdf
    • https://pusotovoxidelo.weebly.com/uploads/1/3/1/6/131637553/3134683.pdf
    • https://nujujuzizupefe.weebly.com/uploads/1/3/1/6/131606206/2366217.pdf
    • http://moymagazin.xyz/metro_last_light_play_orderz7r3h.pdf
    • http://zixudivibudizu.scienceontheweb.net/gazitebikuz.pdf
    • https://bewogataxatux.weebly.com/uploads/1/3/2/6/132695278/8cc96982ed4799b.pdf
    • https://mitafomanamo.weebly.com/uploads/1/3/0/9/130969747/6fb0423d0732f6d.pdf
    • https://tanifovekula.weebly.com/uploads/1/3/1/3/131379991/jotojazepukedes_lutogog.pdf
    • https://regifedemez.weebly.com/uploads/1/3/1/4/131406591/dukafiveneguzadu.pdf
    • http://cenderaoriginator.com/descriptive_essay_example_about_lovepa6q4.pdf
    • https://cdn.sqhk.co/vujejanar/FfFghjh/train_timetable_sydney_to_wollongong.pdf
    • https://nopeludaseji.weebly.com/uploads/1/3/3/9/133986928/mesune.pdf
    • https://cdn.sqhk.co/nufesewepi/tibVI1k/karuppasamy_songs_masstamilan.pdf
    • https://cdn.sqhk.co/nowavutu/ZgifigG/77239674077.pdf
    • https://fetuxugov.weebly.com/uploads/1/3/4/6/134655394/xoxarasekejota-vizufogimitaba-gofinovotisepuj-xajizixabarum.pdf
    • http://nowtorrentz.com/vegepafevebajediphr3m.pdf
    • http://dororuminaxa.mywebcommunity.org/bpsk_adalah.pdf
    • https://libufuvebugun.weebly.com/uploads/1/3/1/4/131406816/8491235.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012010.bin
e08bedf66357a45df42c0c2b77b918fce7275a15725609e56c5701512fa68993
pdf-font-stream PDF embedded font (sfnt) at offset 0x12010 5268 bytes
font_01_sfnt_off000131fa.bin
3bbdb8ab14517dc7099d1bc495fffc49bd7c8d3c6d44fdbf891a1ad117a6870d
pdf-font-stream PDF embedded font (sfnt) at offset 0x131FA 12300 bytes
font_02_sfnt_off00015bcd.bin
2173a1880e9f774f759393e7d0d28dda91d04d8a3eae6bea41b822770b343b90
pdf-font-stream PDF embedded font (sfnt) at offset 0x15BCD 16060 bytes