Malicious PDF — malware analysis report

Static analysis result for SHA-256 129888c50357e7e3…

MALICIOUS

PDF

83.5 KB Created: 2021-03-12 05:21:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d2680b00424a3999de0182f6d6f66b35 SHA-1: d1f4f2bf6d805944a74b10968e7f6d721fe2abc7 SHA-256: 129888c50357e7e31a2ef9059a17e11764969e9f353274ddbbaf0d36b7ee776c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded URLs, many of which are associated with link farms and SEO spam, suggesting a phishing or malicious redirection attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. No scripts were extracted, but the heuristic firings point to a malicious PDF designed to host or link to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9957

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=english+synonyms+antonyms+list+pdf
    • https://nadatipaj.weebly.com/uploads/1/3/5/3/135347779/nerimosiwaze_sevidedelirav_kobewasipo.pdf
    • http://felulam.22web.org/concepto_de_derechos_humanos_onu.pdf
    • https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/jegeris-soneredevexol-donibamadoji-kilorukabire.pdf
    • https://makigomeludawuk.weebly.com/uploads/1/3/4/7/134748455/2c441.pdf
    • http://wepirafigezatid.22web.org/govukomugu.pdf
    • https://luwupedo.weebly.com/uploads/1/3/1/3/131383743/5aec6826.pdf
    • http://monogawuw.iblogger.org/focusrite_scarlett_18i8_garageband.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/medaliwifufugel/what_is_the_rule_for_1_4_9_16.pdf
    • https://28932ed2-21d9-4123-99cb-fcff0aac4472.filesusr.com/ugd/cc089a_5687219fe6554d3eb827b5ebc3ce4550.pdf?index=true
    • https://9a4b5e96-23fe-4021-9525-787506808755.filesusr.com/ugd/b3318b_13419d86355d46549b44bc3cac7f0d50.pdf?index=true
    • http://vowugapawixot.rf.gd/situacin_actual_de_los_derechos_humanos_en_mxico_2020.pdf
    • https://uploads.strikinglycdn.com/files/d6f01d8d-9e7a-418e-a9ea-361a9ebb2278/wanukufugodafufi.pdf
    • https://5c71d6b4-13b5-43a2-97a4-9a0eba4d0f4d.filesusr.com/ugd/0f1814_473c39b0905b4c99aa65eb1cb4309d48.pdf?index=true
    • https://a121017b-3fb3-450c-9156-48dd71a9bf80.filesusr.com/ugd/07625c_7c098504d9714b45ba5551b87e77b7d3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/62a6681b-2ff5-4413-a832-243f6fceb18a/ruger_lcp_2_laser_light_combo.pdf
    • https://s3.amazonaws.com/dowavelaxam/anaganaga_oka_dheerudu_video_songs_mp4.pdf
    • https://uploads.strikinglycdn.com/files/4c89442f-7de8-4f05-a3dd-914c7a81b42e/mubusoxobuwutowuva.pdf
    • https://75a697d3-84f0-44cf-bab9-f05e37020c50.filesusr.com/ugd/7c3584_c109384521ab4a07bb83ca17a8e74286.pdf?index=true
    • https://73a1781f-5c9f-4c76-8a11-a8e8c44f336a.filesusr.com/ugd/d9f7b5_526e35902b4040be9a85d2fdc9d7eb56.pdf?index=true
    • https://dc688580-c0ec-4ade-910b-7abffd870ab4.filesusr.com/ugd/096b61_1908f615a8364bcd9630ca5e7b197b58.pdf?index=true
    • https://171e2b11-24ea-4535-acac-f971ec821c4b.filesusr.com/ugd/a07927_c626015a97234b6baebc333896dcda9f.pdf?index=true
    • http://xevorerokune.epizy.com/91433058950.pdf
    • https://s3.amazonaws.com/xamibudasagas/24300293327.pdf
    • https://uploads.strikinglycdn.com/files/f6d318fe-6030-4daa-9a96-b1344d4e4ecd/pawegap.pdf
    • https://5b949be5-44ef-49af-96c7-0ebaa8fe632e.filesusr.com/ugd/3402b1_bd2337ca47034d91950abdd6de373bc5.pdf?index=true
    • https://s3.amazonaws.com/luxaduzimase/signs_and_symptoms_of_hepatitis_b.pdf
    • https://1cf095b7-1d29-4152-b82c-7733cf7ba0c7.filesusr.com/ugd/c1de29_701cb943e5fc4b53b73e36bb0fc2ed76.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010a28.bin
74c41ec14a393c279a4e4d5d5626c8f3e3f1f24488eac231d53cbb93e6701f08
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A28 5420 bytes
font_01_sfnt_off00011c82.bin
7c5bffc3bb292c801321c190c7c137957c662d2674f20d7bc767a3feea288119
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C82 10500 bytes