Malicious PDF — malware analysis report

Static analysis result for SHA-256 0851a48363e57141…

MALICIOUS

PDF

89.4 KB Created: 2021-04-08 04:37:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bd7d0f4783500f98a7a77bc2667e476f SHA-1: 2378919e815e430c1bd817761dfc60301f0edef1 SHA-256: 0851a48363e571412eea39107028c8ea24d0b9f9a027415a6f5b5147362700cd
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm of external PDFs, with one prominent URL related to medical waivers for the army. This suggests a phishing or scam attempt to redirect users to potentially malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, likely involving the distribution of further malware or phishing content through the linked PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=how+to+get+a+medical+waiver+for+the+army
    • https://kefawefixak.weebly.com/uploads/1/3/0/7/130738991/7916178e4ef9571.pdf
    • https://nabezaxe.weebly.com/uploads/1/3/4/8/134852032/xejubikaxogode-wifirisoxu.pdf
    • https://menanotiji.weebly.com/uploads/1/3/4/3/134322389/fevudux.pdf
    • http://dodemawaj.iblogger.org/the_chainsmokers_closer_lyrics.pdf
    • https://lenonexijinex.weebly.com/uploads/1/3/4/6/134647177/7034582.pdf
    • https://bopamoverera.weebly.com/uploads/1/3/1/4/131408256/kuwadomemibozu_xofimenax_ditubirafut.pdf
    • https://wazexexa.weebly.com/uploads/1/3/5/3/135305699/6528995.pdf
    • http://xejevojesinil.22web.org/hec_lat_test_july_2019_answer_key.pdf
    • https://xibabajawaxas.weebly.com/uploads/1/3/1/3/131398380/mazaramap-tarozeziw-gijowewenapovem.pdf
    • https://lakubamovoto.weebly.com/uploads/1/3/0/7/130776542/fofapofuvavu_deluw.pdf
    • https://panesiwosejel.weebly.com/uploads/1/3/0/7/130739396/pefapukajidisibifi.pdf
    • http://noxudisogukat.iblogger.org/what_does_it_mean_when_someone_says_defying_gravity.pdf
    • https://bodobazanukabub.weebly.com/uploads/1/3/4/8/134889783/ruzivi_wovigipewa.pdf
    • http://wutoxurusot.iblogger.org/college_general_biology_textbook.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/245d7542-3ced-413a-8952-2d0e44a4527a/jerozefuxilowuf.pdf
    • http://weketabafizevu.epizy.com/53416061848.pdf
    • http://korobuvorudetiv.rf.gd/rutijozizidanisesixun.pdf
    • https://s3.amazonaws.com/ropidadegaxut/how_to_fix_le_error_code_on_samsung_dishwasher.pdf
    • https://uploads.strikinglycdn.com/files/91ddd32e-24ab-4822-91de-b64a03e272ff/56607130467.pdf
    • https://s3.amazonaws.com/bomupi/retojujifudafemudope.pdf
    • https://s3.amazonaws.com/pozokimepe/neoclassicism_art_movement.pdf
    • http://lubuzasoxevixan.epizy.com/information_security_policy_template_nist.pdf
    • https://uploads.strikinglycdn.com/files/aad9c1b9-09df-44bc-85a4-7d1d09774c68/benunuvizazorebadelonivow.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011316.bin
b413590b3cd597de10c574bab5b8a0dc4b9a89b783bfc27c0dbda753b744019a
pdf-font-stream PDF embedded font (sfnt) at offset 0x11316 5152 bytes
font_01_sfnt_off000124bc.bin
b23d4c0dc6ab5ee0340f18ac4efc3ed4f0491903358c0d9df6cf0bfd2258ce09
pdf-font-stream PDF embedded font (sfnt) at offset 0x124BC 10876 bytes
font_02_sfnt_off000149b9.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x149B9 4324 bytes