Malicious PDF — malware analysis report

Static analysis result for SHA-256 13da981e89cc58b5…

MALICIOUS

PDF

106.8 KB Created: 2021-03-23 13:15:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 621ccda369b9b791ff0d2319b1abd51c SHA-1: 2b92751e6f2161cbb2cba8067c5793261327535f SHA-256: 13da981e89cc58b54198eadf5a4dd6b2286673bcb0c79a2c10e59834bb081384
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains numerous external links, with a primary link pointing to a suspicious domain associated with SEO manipulation and potential phishing. While no scripts were explicitly extracted, the PDF structure and the presence of external links suggest an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/wix?keyword=the+property+of+cleavage+reflects
    • https://static.s123-cdn-static.com/uploads/4365642/normal_5fcf49cf0cb32.pdf
    • https://sekinejifupom.weebly.com/uploads/1/3/5/3/135350217/jolexa.pdf
    • https://cdn-cms.f-static.net/uploads/4381344/normal_601b2a0d3259b.pdf
    • https://pafovawulawagi.weebly.com/uploads/1/3/4/5/134581771/milewek.pdf
    • https://cdn-cms.f-static.net/uploads/4390643/normal_60264e379e1fe.pdf
    • https://kusugano.weebly.com/uploads/1/3/4/7/134740680/fixup.pdf
    • https://static.s123-cdn-static.com/uploads/4454691/normal_5ffbd9465069a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/b5418fba-1f81-48ba-92b6-d9234afbe01b/42855253657.pdf
    • https://uploads.strikinglycdn.com/files/2e90cdf0-57f6-42b1-9921-dbcade9ef1b9/will_there_be_another_the_mortal_instruments_movie.pdf
    • https://18b62485-dce0-4e35-9712-b1d1f13fcb23.filesusr.com/ugd/296484_6edbfd43e93643348dd1242fec43b3a7.pdf?index=true
    • https://uploads.strikinglycdn.com/files/59abe0a3-6ac3-41c8-8bab-8bbc19798377/7082284863.pdf
    • https://a5a8f6e1-24ae-425c-880d-6f4079e3c376.filesusr.com/ugd/035627_54e415eccee44833826887ac845306aa.pdf?index=true
    • https://5d3a357a-25b2-4459-9cd8-210b235f7b36.filesusr.com/ugd/45e30f_c770687fd07d4f6ea7bd8963559d86e2.pdf?index=true
    • https://6b54b0b2-91db-43cc-88c8-bbc4f7e20b37.filesusr.com/ugd/a773aa_d82ba9d34afa4c669a2f0bf5442eeed1.pdf?index=true
    • https://1fa67a36-2e8b-44cc-a955-751d80433762.filesusr.com/ugd/d85e51_f2240c89fb714f138c7124519d77beed.pdf?index=true
    • https://uploads.strikinglycdn.com/files/001acafa-b7af-4ed9-9df0-4a68dbcef549/tililidanil.pdf
    • https://4121a797-204a-431c-92a8-8e24072fb342.filesusr.com/ugd/b972d5_90fdd505b84a4021a16f57aa7f381ab8.pdf?index=true
    • https://28a90398-13b1-4b58-b54c-ed045a6bddf2.filesusr.com/ugd/7e9e1f_3698dd2dc3664953bf769eacc39661f3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015c7d.bin
dd7b880f1c6958317b71933e3175eb4154b1281d355b69180e4ce829e506ee21
pdf-font-stream PDF embedded font (sfnt) at offset 0x15C7D 2828 bytes
font_01_sfnt_off00016677.bin
9343167e77b8b0415b3a9385f1458282788bd2f9e56cca28e54ad3448c111089
pdf-font-stream PDF embedded font (sfnt) at offset 0x16677 5388 bytes
font_02_sfnt_off000178dc.bin
1a430a3ded56089d9e829144a196529dc923a1306589bd380d1327305813ea54
pdf-font-stream PDF embedded font (sfnt) at offset 0x178DC 10372 bytes