Malicious PDF — malware analysis report

Static analysis result for SHA-256 078e9d5a0a644038…

MALICIOUS

PDF

90.6 KB Created: 2021-03-11 10:46:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0020678faecf714cb8581e7637a41d11 SHA-1: 948ac705cf2c56233ccb20e00953de829d8b3a24 SHA-256: 078e9d5a0a6440383297d8825380563291dac7c7c23ab4fb01905ed4110cac39
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by multiple heuristics and a machine learning classifier. It contains a large number of external links, many of which point to other PDF files, suggesting a link farm or SEO poisoning tactic. The document body, though heavily obfuscated, appears to contain keywords related to popular media, likely to attract user clicks. The primary purpose seems to be directing users to potentially malicious or unwanted content hosted on external domains.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=star+trek+discovery+season+3+episode+6+reddit
    • https://cdn.sqhk.co/rorexamuviz/jewigic/walking_dead_season_10_episodes_air_dates.pdf
    • http://bulugivuto.iblogger.org/best_answer_tell_me_about_yourself_interview.pdf
    • https://cdn.sqhk.co/widexerun/1giFZhe/wavetabelobewiximuz.pdf
    • https://cdn.sqhk.co/guwaloxipete/D4if5ge/online_multiplayer_browser_games_unblocked.pdf
    • https://cdn.sqhk.co/koletexun/hjt2gdN/ringtones_for_iphone_11_pro_max.pdf
    • http://kerefasiputupez.iblogger.org/calculator_file_locker_apk.pdf
    • http://rodsfish.club/jipasiwivepekevaxtl4q4.pdf
    • https://cdn.sqhk.co/jerivudofin/iifhesJ/puppet_pals_apparate.pdf
    • https://cdn.sqhk.co/mipijotom/KejeQY7/texas_a_m_corpus_christi_baseball_twitter.pdf
    • https://cdn.sqhk.co/lawikuto/j41lig0/skyblock_seeds_for_minecraft_pc.pdf
    • https://cdn.sqhk.co/tuforalogidu/XhajeQw/zanuxivovekijul.pdf
    • https://cdn.sqhk.co/toxinize/jThgE5R/54631257877.pdf
    • https://cdn.sqhk.co/fojupigek/ghcnEIg/voltage_drop_testing_fuses.pdf
    • https://cdn.sqhk.co/zasemewiti/ijbibje/vofizutekonitozoruvolinog.pdf
    • http://fejixisuburuza.22web.org/what_is_ch_05_error_lg_air_conditioner.pdf
    • http://teksalle.xyz/297254353279ygok.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://kiguwodakoz.rf.gd/what_is_the_best_fishing_brand.pdf
    • http://guxajez.rf.gd/ruparowiwatasitefo.pdf
    • https://2061f665-9309-41a6-981d-137229ee7e60.filesusr.com/ugd/eb2fe6_bc112a2ea65c47228e74e05334586052.pdf?index=true
    • https://c6111751-42b6-464f-a8b1-832d492ff999.filesusr.com/ugd/3d0627_7023bad75b6949a7a17f806d29ee106b.pdf?index=true
    • https://ad0d0dbb-669b-46a9-85df-79487014a0f3.filesusr.com/ugd/00d95d_d6f88d37ce844e0f82f6c98702484aae.pdf?index=true
    • https://9764c975-acb6-4bd5-a3ff-b1f4624bc9bc.filesusr.com/ugd/5bcb7b_2e3d9de7c6374c5d9a7f2946e19aeadb.pdf?index=true
    • https://f55c6975-0091-4942-a106-dc80285e5f9d.filesusr.com/ugd/8a4248_07e206e58f9645c0ae519d878c73e68f.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012444.bin
34beda45c838fc8192c4505342eeaeaa9fb145bd74290171a197a6fac769b629
pdf-font-stream PDF embedded font (sfnt) at offset 0x12444 5680 bytes
font_01_sfnt_off000137b9.bin
9108cfa273d93aee631d16d214dfadd61a23175937c209b5b7fcf3b55cd64b0f
pdf-font-stream PDF embedded font (sfnt) at offset 0x137B9 10900 bytes