Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bdeb2679f314069…

MALICIOUS

PDF

76.0 KB Created: 2021-03-23 20:13:31 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2bbbc65b51cff4f7179bfedb110764a8 SHA-1: 9b6b8ae8433803ab3d2cb68e26f1cf29fa3048cb SHA-256: 0bdeb2679f314069723278b46b5ece4d840fd949f08702958983761e5469d2ac
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file, disguised as a document about love poems, contains a significant number of external links, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent, likely to redirect users to phishing or malware-hosting sites. No scripts were extracted, but the presence of numerous external URLs is the primary indicator of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/aws?utm_term=love+poems+for+a+husband+from+the+heart
    • https://cdn.sqhk.co/dikonutudibe/3ijZzAU/zetukimasoka.pdf
    • http://smartcoin.design/grounding_exercises_for_dissociationy8wdf.pdf
    • https://cdn.sqhk.co/nefikelifu/dCidjdj/99073562770.pdf
    • https://cdn.sqhk.co/fetebutujo/83MMmSD/pac-_man_championship_edition_2_switch.pdf
    • https://cdn.sqhk.co/wuzevunoxina/idq9Els/bugaboo_cameleon_repair_manual.pdf
    • https://cdn.sqhk.co/towinomer/eghm4ia/10495409693.pdf
    • https://cdn.sqhk.co/kopilixa/iibeGjf/9244950930.pdf
    • https://cdn.sqhk.co/datolabevev/ijexjgM/kenigixopowubekaxes.pdf
    • https://cdn.sqhk.co/pozazoji/chalnia/fevabopofavibovito.pdf
    • http://vizionsmc.net/80369896818x7qoq.pdf
    • http://avlto.best/sundance_spa_filter_chartkoo7i.pdf
    • http://jopkapopka.online/28789308146aky79.pdf
    • http://tryne.xyz/ninijirlklhj.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/8b7874a2-5a08-4b8d-b300-2dbaa703df51/which_phones_support_qi_wireless_charging.pdf
    • https://uploads.strikinglycdn.com/files/9a1958da-3543-4a01-961b-f0a1ffb989a1/taking_care_of_wife_quotes.pdf
    • https://d046670e-94b8-4ea2-8efc-69fca9b502c9.filesusr.com/ugd/c0b427_513c9190c37a4e7a880534d08b26ca81.pdf?index=true
    • https://5d94d51b-2702-4b64-8df3-eadd022f3edc.filesusr.com/ugd/2ddd39_5a0847ab66cc40f78c7b91e861d1358c.pdf?index=true
    • https://uploads.strikinglycdn.com/files/1f67ccff-96d0-4335-9a69-bc0fb43db43c/19892910893.pdf
    • https://uploads.strikinglycdn.com/files/ce675966-8b8a-4f51-a0dc-aab77ffaebc0/zovikevomigopinojelozu.pdf
    • https://uploads.strikinglycdn.com/files/d6ff0363-81d3-4c9f-ad4c-500bfacb0599/act_2016-17_practice_test_answers.pdf
    • https://184d393c-d2ff-49e5-bbcb-48626b1dbf88.filesusr.com/ugd/49be48_d67f01147a964542af34a4c14d23f931.pdf?index=true
    • https://aefbb2f1-1cfc-4a48-aab2-d72547d84173.filesusr.com/ugd/2f3ac6_1912e0b3129d4a4b8bcafe280a75c8ef.pdf?index=true
    • https://uploads.strikinglycdn.com/files/6b1e2d28-480d-408e-9a33-eaf294eb34ac/xolokoboj.pdf
    • https://uploads.strikinglycdn.com/files/a82472ae-2ee7-4a1c-9b08-aebee0c38f3b/88034069363.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebb7.bin
e9d7d3c2ec00c5dc1e2cf4743f8927b2f58cdcf701d6fac048cb2e0cbdb862e4
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBB7 5392 bytes
font_01_sfnt_off0000fde6.bin
529a5e289de8cf50bf3466516aa9e197cd181350ac9510a93c45b4f6336f28a0
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDE6 10040 bytes