Malicious PDF — malware analysis report

Static analysis result for SHA-256 07e02b63c021dc3c…

MALICIOUS

PDF

81.4 KB Created: 2021-05-28 21:32:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6ced31e293f5c490cd8b907a4916dbcc SHA-1: 7dc10c98ec96308c2b947fa61f0f2058b8c763b5 SHA-256: 07e02b63c021dc3cc8fe50eca8a98979d7bfae9140daf281d0771729442121b6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many pointing to PDF files hosted on various domains, suggesting a link farm or phishing operation. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as 'Pdf.Phishing.Trojan'. The document body, though heavily garbled, appears to be related to an academic assignment, likely a lure to disguise the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9975

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=bilimsel+ara%25C5%259Ft%25C4%25B1rma+y%25C3%25B6ntemleri+final+%25C3%25B6devi
    • https://cdn-cms.f-static.net/uploads/4369166/normal_6026adbbd6408.pdf
    • https://sebeguresed.weebly.com/uploads/1/3/5/9/135966133/4324489.pdf
    • https://static.s123-cdn-static.com/uploads/4454995/normal_60031ae0dea4d.pdf
    • https://fosijegaden.weebly.com/uploads/1/3/4/8/134868146/libizevulamiboj-winuvanot-pepuzuw-bumimajazobi.pdf
    • https://namuxewanazojo.weebly.com/uploads/1/3/4/2/134266474/gadidigetizasugi.pdf
    • https://vakurizilobiwil.weebly.com/uploads/1/3/0/9/130969742/saxugivevodugaz.pdf
    • https://cdn-cms.f-static.net/uploads/4495269/normal_60298abeab572.pdf
    • https://cdn-cms.f-static.net/uploads/4490250/normal_6062753e20edf.pdf
    • https://cdn-cms.f-static.net/uploads/4388174/normal_5fe6f9575830e.pdf
    • https://static.s123-cdn-static.com/uploads/4446646/normal_5fe2e5119d3ab.pdf
    • https://static.s123-cdn-static.com/uploads/4481162/normal_5ffe214051ff8.pdf
    • https://fuvetozexogix.weebly.com/uploads/1/3/0/8/130874326/waxisoti_kogusuneb.pdf
    • https://tedipoji.weebly.com/uploads/1/3/1/4/131408178/zemopolov_sekazifagesu.pdf
    • https://cdn-cms.f-static.net/uploads/4485569/normal_602ce47abd168.pdf
    • https://safubijob.weebly.com/uploads/1/3/2/6/132682970/xutokedifelug_zeguwepekez_nejewox.pdf
    • https://jijubukaxujofi.weebly.com/uploads/1/3/4/8/134892288/xixosixotexaw.pdf
    • https://bevibobozile.weebly.com/uploads/1/3/4/7/134700853/poduboguf-ridekokelos-wejoxadufefavor.pdf
    • https://sikufotoxatufik.weebly.com/uploads/1/3/4/4/134458503/6ba56c237210.pdf
    • https://nudegono.weebly.com/uploads/1/3/4/6/134682657/fewekewipab.pdf
    • https://sulunekuzesafap.weebly.com/uploads/1/3/1/4/131406846/linowetirosenigaxi.pdf
    • https://jugozufenuw.weebly.com/uploads/1/3/4/2/134266135/f0d5ceadbfba08b.pdf
    • https://fapifejoj.weebly.com/uploads/1/3/4/2/134265577/gagilaviz.pdf
    • https://vafumavuforowa.weebly.com/uploads/1/3/4/4/134489815/39d306a6b2.pdf
    • https://static.s123-cdn-static.com/uploads/4444655/normal_5ffd660e7932b.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d100.bin
1b2ebf3a0fb1915941ff38a701147ae6760bfb11416b77bdb5cb1b383e859b0c
pdf-font-stream PDF embedded font (sfnt) at offset 0xD100 3088 bytes
font_01_sfnt_off0000dbff.bin
499ab6f2a641b66cce3b4fffade756ca9c8c0ffc7a8cbd2f94c6a12c22cad1c4
pdf-font-stream PDF embedded font (sfnt) at offset 0xDBFF 5360 bytes
font_02_sfnt_off0000eda0.bin
94b8362271490221f48010a5275d6fc2118edfcc6a54f4f0f47cfcc931f1836b
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDA0 10688 bytes
font_03_sfnt_off0001115a.bin
23225a3811002c52a9663c4b26af39ba7190a42f2a8e0f986dd3c19595457f66
pdf-font-stream PDF embedded font (sfnt) at offset 0x1115A 16180 bytes
font_04_sfnt_off0001268a.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x1268A 4324 bytes