Malicious PDF — malware analysis report

Static analysis result for SHA-256 11d6eaeddf211639…

MALICIOUS

PDF

86.6 KB Created: 2021-03-20 02:43:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e0e3473bcf12b4b19d35cef7c5140ddf SHA-1: 7b02a431aaa2cfb11451e405b31adabfb1f2a20e SHA-256: 11d6eaeddf2116395f7fa28683513a88dcf30aaf4229fbc18a4062308e8f6323
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for SEO spam or phishing campaigns. ClamAV and ML classifiers flagged this as malicious, specifically a phishing trojan. The embedded URL 'https://vilenefex.ru/strik?utm_term=dream+interpretation+teeth+falling+out+definition' is likely the primary malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=dream+interpretation+teeth+falling+out+definition
    • http://kifikawi.66ghz.com/who_guards_the_prime_minister_of_canada.pdf
    • https://static.s123-cdn-static.com/uploads/4449602/normal_5fdda5136c354.pdf
    • https://soxapibojewaw.weebly.com/uploads/1/3/5/3/135345372/6911492.pdf
    • https://static.s123-cdn-static.com/uploads/4446036/normal_6007d10a38614.pdf
    • https://cdn-cms.f-static.net/uploads/4466172/normal_602e5eb2961b0.pdf
    • https://cdn-cms.f-static.net/uploads/4456116/normal_5fd1e50cf3c44.pdf
    • https://benipotuwazel.weebly.com/uploads/1/3/4/4/134445242/9510253.pdf
    • https://cdn-cms.f-static.net/uploads/4384154/normal_6032303060296.pdf
    • http://gakebapenabe.iblogger.org/51107192352.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/5fc48e8f-3d89-42db-8056-fc0601690d7b/how_to_repair_your_car_in_gta_5_cheat.pdf
    • https://uploads.strikinglycdn.com/files/5ee34eef-e1e9-4a38-9d3a-a2c6e96cb562/was_the_forrest_fenn_treasure_found.pdf
    • http://zoletiwosi.rf.gd/goku_vs_android_19_full_fight.pdf
    • http://gepuxaxevo.rf.gd/free_calling_application.pdf
    • https://uploads.strikinglycdn.com/files/b6555d3e-c87c-443e-921f-b0dbb410edb6/lirebowipovekimagalep.pdf
    • https://uploads.strikinglycdn.com/files/b10dad09-60e6-4be7-914f-47ff208738b9/how_to_turn_on_ringer_on_avaya_phone.pdf
    • https://e1ca4115-fb55-43f9-84f1-eaf814f8c83f.filesusr.com/ugd/18122d_ee45da145cba4c14a15117a82f4b2777.pdf?index=true
    • https://uploads.strikinglycdn.com/files/311a42a3-14dc-49e8-9110-b90f74ada5c9/how_to_knit_entrelac_instructions.pdf
    • https://627f215e-41ba-4aa4-9906-5f9f9d117739.filesusr.com/ugd/8ab72e_73e4cc15b69f48cbb2e11c6485f2b74e.pdf?index=true
    • http://difugarulid.epizy.com/sejigulifevunaroduxeduro.pdf
    • https://uploads.strikinglycdn.com/files/feacc996-b0f5-4931-8212-5b08890ad747/what_is_the_definition_of_romance_in_literature.pdf
    • https://uploads.strikinglycdn.com/files/5b302221-10e4-4cf7-afc5-292089466deb/craftsman_3_gallon_air_compressor_replacement_parts.pdf
    • https://uploads.strikinglycdn.com/files/f2c82bc2-6913-4a19-a3b4-3c7e17653b85/what_are_the_five_senses_called.pdf
    • https://uploads.strikinglycdn.com/files/2600a658-5927-42e6-b5f3-ec009dd73c2f/19426811370.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000113c1.bin
e9843c5f4803ec27e17320367d7d0c925dac08843fe905fa1cd1bf31f293e9e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x113C1 5276 bytes
font_01_sfnt_off00012594.bin
7e4c791cb942405636d0f2a6b15e11af7dd6ddc3d0e20fa10a336dd8f1bd4a75
pdf-font-stream PDF embedded font (sfnt) at offset 0x12594 10764 bytes