Malicious PDF — malware analysis report

Static analysis result for SHA-256 06972fa0d9c4c9eb…

MALICIOUS

PDF

74.2 KB Created: 2021-05-18 08:52:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 41b52ddf041afa3e787fd73681d50be0 SHA-1: 7c1c53db6bc6279528d779c0b2e15d4b30964a16 SHA-256: 06972fa0d9c4c9eb153c1d4f6cf6fdd77ce59de6ea5ee184f8acc2716ab50f17
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains a large number of external links, suggesting it is part of an SEO spam or phishing campaign designed to drive traffic to potentially malicious websites. The document body, though heavily obfuscated, references "Washburn banjo serial numbers", likely a lure to attract victims.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9948

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=washburn+banjo+serial+numbers
    • https://cdn-cms.f-static.net/uploads/4471692/normal_6040566124585.pdf
    • http://tinewipikawulu.iblogger.org/defiant_outdoor_heavy_duty_timer_instructions.pdf
    • https://static.s123-cdn-static.com/uploads/4479212/normal_6008d6e144157.pdf
    • https://cdn-cms.f-static.net/uploads/4498678/normal_606b294e02a73.pdf
    • https://static.s123-cdn-static.com/uploads/4421960/normal_6003403c33152.pdf
    • https://cdn-cms.f-static.net/uploads/4368467/normal_5fd7b9a742863.pdf
    • https://cdn-cms.f-static.net/uploads/4451945/normal_600b056742e92.pdf
    • https://cdn-cms.f-static.net/uploads/4417808/normal_605ef5cd93f54.pdf
    • https://cdn-cms.f-static.net/uploads/4450512/normal_601a799bea80a.pdf
    • https://nupimixek.weebly.com/uploads/1/3/2/7/132712066/cc172b77d.pdf
    • https://keregejuvuja.weebly.com/uploads/1/3/4/3/134345288/guzuzufulukud.pdf
    • https://nulebuset.weebly.com/uploads/1/3/1/4/131411431/firavusemegame-sikutasoz-suwinojazu-bavoxu.pdf
    • https://cdn-cms.f-static.net/uploads/4487007/normal_5fdc44ad4bbd1.pdf
    • https://cdn-cms.f-static.net/uploads/4374540/normal_606e2d8352d71.pdf
    • https://cdn-cms.f-static.net/uploads/4479938/normal_60317c1e43029.pdf
    • https://zegazofegu.weebly.com/uploads/1/3/5/2/135296009/sezejemoguwakotopo.pdf
    • http://sejapamuji.22web.org/dolezataxamem.pdf
    • https://static.s123-cdn-static.com/uploads/4490920/normal_6007befe40bb4.pdf
    • https://cdn-cms.f-static.net/uploads/4408004/normal_601107eb18ed9.pdf
    • https://cdn-cms.f-static.net/uploads/4415051/normal_6026b0f68d165.pdf
    • http://bapipakaroxi.22web.org/problemas_de_aprendizaje_concepto.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://pubitawiwinas.rf.gd/xufijunebugodinale.pdf
    • http://vipuzot.rf.gd/93841916240.pdf
    • http://xadokij.epizy.com/gospel_of_barnabas.pdf
    • http://kotanefizipabu.rf.gd/ranukupelaxusovo.pdf
    • http://rixuzomobe.epizy.com/bidovedakej.pdf
    • http://pobediwawe.epizy.com/sipejubomar.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da24.bin
7c43005bcd0488bdd513ea7e9a0342c424f2c5c860af35d3a3553b8f4476a5ef
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA24 4956 bytes
font_01_sfnt_off0000ead0.bin
0d66721a3abeb41881ad90c168b752c2aba5d94cba6b769a116bbfb52220bc20
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAD0 10020 bytes
font_02_sfnt_off00010d18.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D18 4324 bytes