Malicious PDF — malware analysis report

Static analysis result for SHA-256 10c06b8637867b10…

MALICIOUS

PDF

69.1 KB Created: 2021-03-15 00:56:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f178677da356734244f68eb85536881f SHA-1: d6ecf55705cdc253fe98007aaa8ddc045e95b1b4 SHA-256: 10c06b8637867b10756c193fa8447e48f025d69a259d794c14c4eae126646b1b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are obfuscated or lead to potentially malicious content, as indicated by the 'PDF_SEO_LINK_FARM' and 'ML_NYX_PDF_MALICIOUS' heuristics. The ClamAV detection further confirms its malicious nature, identifying it as 'Pdf.Phishing.Trojan'. The embedded URLs suggest an attempt to redirect users to phishing or malware download sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/123?utm_term=simple+business+plan+for+students+pdf
    • https://cdn.sqhk.co/lumolixuwo/5ddX9t9/the_battle_cats_mod_hack_download.pdf
    • https://cdn.sqhk.co/gesuxafom/gijjNUE/sisters_of_mercy_urgent_care_brevard_north_carolina.pdf
    • https://cdn.sqhk.co/vumorumuvogi/E6igHih/69220741585.pdf
    • http://vizezokope.iblogger.org/34010957797.pdf
    • http://kofefolo.22web.org/komifofizi.pdf
    • https://cdn.sqhk.co/lilapanorup/iiNjaih/max_air_bmx_glitch.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://wofuxax.rf.gd/dewalt_dw402_parts.pdf
    • https://uploads.strikinglycdn.com/files/923ec214-a88d-4fc8-965a-9baa2063ba8e/the_lion_king_full_movie_1994_english.pdf
    • https://6739ca04-605d-4ff4-b4c9-4e5bd75a7819.filesusr.com/ugd/031dda_6dbb5f6ab5c64428a311af9a4194f9ad.pdf?index=true
    • https://944456f3-75eb-4cd6-bbfd-656b3713ada1.filesusr.com/ugd/2c8d66_79af2856ab484a98acca99270eacdafb.pdf?index=true
    • https://uploads.strikinglycdn.com/files/db1af26b-27aa-4d7e-b6d8-bd60a7ac0867/what_is_a_kabar_fighting_knife.pdf
    • http://goziwofa.rf.gd/96860628749.pdf
    • https://uploads.strikinglycdn.com/files/db4becd2-1956-420a-9680-5676d321196f/kovoximigopujirimobifajo.pdf
    • https://91313464-3f42-441e-b0e8-b27065d471ad.filesusr.com/ugd/ee9d3f_140e7c52267d47e58172ce29c7f96530.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e0a965e5-8b65-46f5-bcb2-3f12b32a1521/financial_algebra_advanced_algebra_with_financial_applications_1st_edition.pdf
    • https://uploads.strikinglycdn.com/files/2d244e96-f104-47a2-b731-c1a110986d78/11659129733.pdf
    • https://f06ae689-34e6-4fd9-b749-a5985747e370.filesusr.com/ugd/4117a9_9a26c07442eb43d9bea94486990dc2ca.pdf?index=true
    • https://uploads.strikinglycdn.com/files/06d674fd-8f64-48a5-9863-a2b395e62f21/lusesiloxosigamaxiwaxod.pdf
    • https://uploads.strikinglycdn.com/files/3e368f9f-5e13-469f-b1a5-c58fcfeded40/how_do_i_make_my_defiant_motion_light_stay_on.pdf
    • https://6f4861c6-cdf0-4a5f-ba2d-f9c5e5bfbee6.filesusr.com/ugd/77941b_ea9b85beb6d947fcbdbc685c04fa5cb1.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d060.bin
8a85c728be777ca1dee64d86617aef356c882528ea05f17d675ee5f1ed223afe
pdf-font-stream PDF embedded font (sfnt) at offset 0xD060 5428 bytes
font_01_sfnt_off0000e2b0.bin
034c7b7ed5716782e2121ace6910dc073e70becc25ce494b44072e07eb67b989
pdf-font-stream PDF embedded font (sfnt) at offset 0xE2B0 10748 bytes