Malicious PDF — malware analysis report

Static analysis result for SHA-256 11be0495cce49ac0…

MALICIOUS

PDF

76.4 KB Created: 2021-06-01 09:36:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 16433040af8eb00af5a2aa74611a69e4 SHA-1: d514cc60182032efe547dcd102fd27da4ad1c48c SHA-256: 11be0495cce49ac0b101be025e3bcb1b69b6e8a2994e84e384e005ccea65609f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to benign-looking documents, but one prominent URL, 'https://pixomot.ru/pbw?utm_term=who+is+the+richest+person+in+the+world+2021+april', suggests a lure for users searching for financial information. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware delivery. No scripts were extracted, but the PDF structure itself is used to host and present these links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pixomot.ru/pbw?utm_term=who+is+the+richest+person+in+the+world+2021+april
    • https://noxojinuk.weebly.com/uploads/1/3/4/4/134479051/fazewizi.pdf
    • https://mawijazug.weebly.com/uploads/1/3/1/3/131380733/mowizajasados-telivefiwuw-mojurovomoga.pdf
    • https://masizomomom.weebly.com/uploads/1/3/2/6/132681315/musuwusema-doxixifina-lapajifatot.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://kolasotosexu.pbworks.com/w/file/fetch/144424461/bhakti_gana_dj_remix_song_video_2018.pdf
    • https://uploads.strikinglycdn.com/files/e2e807ef-289d-42ff-a3b0-45d06315dc03/87857643368.pdf
    • https://uploads.strikinglycdn.com/files/7d53bb95-7ea1-4f5d-8b41-29f6e69c0ed4/20034310760.pdf
    • https://uploads.strikinglycdn.com/files/db5fb77e-55d0-4a59-b5d6-0ce65bc84cb0/begeduberuladejupin.pdf
    • http://zopujoxobug.pbworks.com/w/file/fetch/144412131/80000745359.pdf
    • https://uploads.strikinglycdn.com/files/1b4ed39a-a50d-46be-b576-2a77654143f9/what_are_the_types_of_irregular_verbs.pdf
    • https://uploads.strikinglycdn.com/files/d9bbd42e-2b0a-4783-a045-274336c23787/muzas.pdf
    • https://uploads.strikinglycdn.com/files/3bb3d54f-a4e2-4e19-b7a5-6dffa3cf7c3e/excellence_el_carmen_building_map.pdf
    • https://uploads.strikinglycdn.com/files/9359162f-1c45-4509-a85a-89c296ccb81d/baruboviwa.pdf
    • http://lekuzax.pbworks.com/f/ejercicios_de_matematicas_para_segundo_grado_de_secundaria_resueltos.pdf
    • http://wiwedano.pbworks.com/w/file/fetch/144427248/jidelimeterodugitet.pdf
    • https://uploads.strikinglycdn.com/files/6c9ff770-8295-4e39-9f29-1757398ee3c3/landforms_and_changes_worksheet_answers.pdf
    • https://uploads.strikinglycdn.com/files/f9546b45-efdf-462b-b16c-3f65ff339d16/solid_oak_study_desk_for_sale.pdf
    • https://uploads.strikinglycdn.com/files/c89a50b7-8de6-4a10-81e0-87ad3d1f496c/integral_2_sin_x_-_3_cos_x_dx.pdf
    • https://uploads.strikinglycdn.com/files/3fe549ba-7b1f-4995-902a-273c783e2b13/how_to_install_vcruntime140.dll_in_windows_8.pdf
    • http://runaliguredu.pbworks.com/w/file/fetch/144442815/how_to_read_computer_binary_code.pdf
    • https://uploads.strikinglycdn.com/files/7cf0297f-458d-4248-b8f3-d20ae867c64f/mass_effect_andromeda_vetra_romance_guide.pdf
    • https://uploads.strikinglycdn.com/files/4cb5c331-68a5-4204-b869-519a489f4882/how_to_proxy_vote_uk.pdf
    • https://uploads.strikinglycdn.com/files/74ad9b46-d97a-48a4-8cb1-12a9507a49ff/telsta_a28d_service_manual.pdf
    • https://uploads.strikinglycdn.com/files/7dba1f3a-ea6c-4e5a-8854-def7ad10c5cf/how_to_start_a_retail_business_in_india.pdf
    • https://uploads.strikinglycdn.com/files/78c447e0-63e2-47b0-adf7-b2442a942f0e/13164406310.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ebbf.bin
acb656f2ca5c7aab6f90b359adf88c8205b496a906d46728c729ec8b8792f73e
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBBF 5592 bytes
font_01_sfnt_off0000fedf.bin
73fa2d68218d50ac7949d533c42dc62c58d3c45dcb2e48ab2c49e2221d96c8f5
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEDF 10904 bytes