Malicious PDF — malware analysis report

Static analysis result for SHA-256 1500da0cf5e52a71…

MALICIOUS

PDF

93.4 KB Created: 2021-03-21 11:49:09 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5a1fe2fa0fbb861695cdf3648461cc1a SHA-1: 91686b5b8265c2cb9235df5d60d4bc8a627c7bb6 SHA-256: 1500da0cf5e52a712f5c6648b0ac9bbd429018249d51ae88d5bf45a26ce5a594
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection for Pdf.Phishing.Trojan. The PDF contains a large number of external links, suggesting a link farm or phishing attempt. The embedded URLs point to various domains, some of which are likely used to host further malicious content or redirect users to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/wix?keyword=inuyasha+naraku+baby
    • http://vebuwovivulab.mygamesonline.org/sdgs_goals.pdf
    • http://pesuloduf.medianewsonline.com/ncfm_fundamental_analysis_book.pdf
    • http://lakuberik.mywebcommunity.org/waking_life_movie_script.pdf
    • https://cdn.sqhk.co/tujuvemevo/jd31uhj/bay_of_bengal_tamil_song.pdf
    • https://cdn.sqhk.co/rumoligodo/hjdheia/84263026851.pdf
    • https://lokulubebu.weebly.com/uploads/1/3/1/8/131856352/8254241.pdf
    • https://xazujojupise.weebly.com/uploads/1/3/4/4/134493550/gesanixejaboba.pdf
    • https://pesuwoleze.weebly.com/uploads/1/3/5/2/135295903/fafezobiwasojep-fupebuxeg.pdf
    • http://serarudipiwuvon.mypressonline.com/uveitis_anterior_adalah.pdf
    • http://lozejebivo.scienceontheweb.net/classical_conditioning_theory_in_classroom.pdf
    • https://sugopubix.weebly.com/uploads/1/3/1/6/131637077/rumolutid_musexutodakawuf_sivuliritipivet_vokezipukeg.pdf
    • http://vopukisavenif.medianewsonline.com/61368901011.pdf
    • https://cdn.sqhk.co/wujakegu/je2s2sj/zufadimaxaxodusezoga.pdf
    • https://powizosiki.weebly.com/uploads/1/3/4/0/134041047/fc1782c.pdf
    • http://fajujefa.getenjoyment.net/52162535995.pdf
    • http://posiximuteg.sportsontheweb.net/galol.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://1237a3da-0b33-4890-9ba9-974507bf2590.filesusr.com/ugd/3e0cb9_04e0ead94a27413a80a5ae3f0fe0372e.pdf?index=true
    • https://a2214900-82f6-4ed5-a432-d5ffd14110fa.filesusr.com/ugd/306b6b_3ffb1c438aab41669c3cfa365296c6bc.pdf?index=true
    • https://f495c71d-628d-4070-9a3d-b699cbb46ba4.filesusr.com/ugd/d99ef3_5a133c7f1f644d5a95d45419da9d383c.pdf?index=true
    • http://sisufovofow.atwebpages.com/97010792482.pdf
    • https://e3055f73-6236-423b-b810-4bc1a15f300f.filesusr.com/ugd/fa12d1_3f77f28052f848ee96e71b22b0485d2a.pdf?index=true
    • http://lodumojokexiku.onlinewebshop.net/lasitifibomano.pdf
    • https://064d663d-f6b2-44cf-a6ad-083da5f315e5.filesusr.com/ugd/77eba6_ee287c1b870146d5aa6a352a2339294f.pdf?index=true
    • https://eaae50f7-3b1c-4f1b-9b3c-e2a48377569d.filesusr.com/ugd/b96e41_b04c82ec45b14b2a97df27c779f532aa.pdf?index=true
    • https://3dd85f33-233b-4b3c-8e53-142bc8307eec.filesusr.com/ugd/8df890_f0b0373d50ed4ae5952d0e6871ec60f2.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011fd4.bin
29b9dbf6733db27b64006191ba3874843de8e17452621b04435d9bf685bae7ce
pdf-font-stream PDF embedded font (sfnt) at offset 0x11FD4 4856 bytes
font_01_sfnt_off000130f6.bin
20b4637c12e0ac288e7a69791483a16186bac72f870cb79edf57908841331ae4
pdf-font-stream PDF embedded font (sfnt) at offset 0x130F6 4984 bytes
font_02_sfnt_off000141e6.bin
5fbac3d1897d4ed3e0537cfff0b323afebe04027a0a002cf03785f7b8adb06df
pdf-font-stream PDF embedded font (sfnt) at offset 0x141E6 11284 bytes