Malicious PDF — malware analysis report

Static analysis result for SHA-256 0497d693c556a05e…

MALICIOUS

PDF

79.2 KB Created: 2021-03-16 05:38:22 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 95027a1b466645b9addd42fda75a2db3 SHA-1: e2c2b861b1609a35bc41fa0e2c0eb42038930f49 SHA-256: 0497d693c556a05e76feb6f1a918756b2b2277cb8d2ef418ae8e0df8dc6ca6fd
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document contains a large number of embedded links, many of which point to external, potentially malicious sites, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware distribution. The document body's garbled content and the presence of numerous external links suggest an attempt to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=money+macro+and+finance+society
    • http://masito.space/gekufitebaplklh4.pdf
    • http://arm-watch3.club/95752420260e6njs.pdf
    • http://familyit.pro/50920951543c5y65.pdf
    • http://feludekinopotas.scienceontheweb.net/48710701194.pdf
    • http://znakomstva18x.site/tixatoxakumeit85b.pdf
    • http://gowanenutik.mypressonline.com/94444383400.pdf
    • http://tinesemexogo.mygamesonline.org/baixar_editor_gratis_portugues.pdf
    • http://ttop-shop.com/64611451737smzvh.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://e6f9d1db-9bad-45ba-a188-0e8e378e8087.filesusr.com/ugd/99b222_920a91a9644a449cbd51f2f8d7b3cdfd.pdf?index=true
    • https://f06ae689-34e6-4fd9-b749-a5985747e370.filesusr.com/ugd/4117a9_8fd9cb0ab3284044b1eaa05b5178e7c8.pdf?index=true
    • https://97783159-ced7-426e-9fbd-60d2bb3342fb.filesusr.com/ugd/00058f_af534627795f4c97a76891580c703d6d.pdf?index=true
    • http://bipunasozusi.epizy.com/brussels_travel_map.pdf
    • https://36622f5a-5a1b-41a5-aa98-965156e47ac2.filesusr.com/ugd/804ff6_3cd76c3477ea4cb5b844aed80993fa40.pdf?index=true
    • https://ec08fec6-e576-400d-8504-372613838d3c.filesusr.com/ugd/57e0ce_14dba2a4e30e461e8e4ca0613ce5c8ad.pdf?index=true
    • https://s3.amazonaws.com/vuforewebub/59701165251.pdf
    • https://s3.amazonaws.com/numunenoji/gentri_abide_with_me_sheet_music.pdf
    • https://409b2d23-5c1d-402e-97df-26c0da9299b0.filesusr.com/ugd/2e3d42_8c85a9b97de7453db13c4e713c6f1de1.pdf?index=true
    • https://a815f367-2516-4b88-9496-eed07d5c1eb7.filesusr.com/ugd/665c20_7e4de967858e484a9907052fe420806f.pdf?index=true
    • https://s3.amazonaws.com/nilafafakem/48178607041.pdf
    • https://s3.amazonaws.com/vipinib/guvuxomuxilari.pdf
    • http://xidozuk.rf.gd/how_do_i_program_my_overhead_door_codedodger_remote.pdf
    • https://abaaaae4-9231-44fc-b12c-ad55ebcc68e7.filesusr.com/ugd/2ca09c_3dc44de8be1540d9a55f599ca07cff63.pdf?index=true
    • http://zupotid.epizy.com/adjectives_intensifiers_worksheet.pdf
    • https://77483064-5892-4b52-b419-66e751946b77.filesusr.com/ugd/ef7b09_4d943610cd674d36aea4275693695e79.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f6ee.bin
8135cae1b7e71613ecf7e2dcf592556bbe53e499800c8ab095c8db8a5048ec81
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6EE 5244 bytes
font_01_sfnt_off000108bc.bin
b43a01715fd2791155c6f2fe0e5620e9d77e6848e7d3bccd5bd70560ce586a4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x108BC 10652 bytes