Malicious PDF — malware analysis report

Static analysis result for SHA-256 173bc55dafc69a6c…

MALICIOUS

PDF

90.7 KB Created: 2021-03-14 21:22:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 64f8b3605aa05de24c6b548d53d2c8ca SHA-1: e2f5d0b8cc61640f661ad061866a94b991a68f7a SHA-256: 173bc55dafc69a6c9fbc6ae9e9aca4a04e0d4b177dcb8a55975590af33d54cc1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-themed, suggesting a link farm or phishing operation. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URL 'https://midufefew.ru/wix?keyword=tearaway+unfolded+trophy+guide' is likely used to redirect users to a malicious site, potentially for phishing or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=tearaway+unfolded+trophy+guide
    • https://cdn-cms.f-static.net/uploads/4383917/normal_601875ec678b4.pdf
    • https://cdn.sqhk.co/motanunika/iigfvii/pocket_door_installation_instructions.pdf
    • https://cdn.sqhk.co/feketukadoz/hdhhyd2/horizon_t303_treadmill_australia.pdf
    • https://cdn-cms.f-static.net/uploads/4447436/normal_604a90b9a55a3.pdf
    • https://cdn-cms.f-static.net/uploads/4417418/normal_603d4b463b6d5.pdf
    • https://cdn.sqhk.co/kelifevaz/gcjaQgi/90424569211.pdf
    • https://cdn-cms.f-static.net/uploads/4417141/normal_5fe8cecf2ea0e.pdf
    • http://rasazajafatirek.mypressonline.com/84354650459.pdf
    • https://cdn.sqhk.co/dolubivo/he4gjif/56659175239.pdf
    • https://cdn.sqhk.co/mixenezir/gghMiek/baby_shark_trip.pdf
    • http://jedusajinud.mygamesonline.org/xikitewukugoxapu.pdf
    • https://cdn.sqhk.co/kojogitu/7ihgjhc/shoot_bubble_fruit_splash_descargar.pdf
    • https://cdn.sqhk.co/wugeguxu/jjchcgc/the_nut_and_bolt_store_hove_bn3_5ql.pdf
    • https://cdn-cms.f-static.net/uploads/4448735/normal_603c28d660144.pdf
    • https://cdn.sqhk.co/fokudiwun/jbM0iij/crossing_over_meiosis_diagram.pdf
    • https://static.s123-cdn-static.com/uploads/4376379/normal_5ff29d58e61aa.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://2c91b947-1dd8-401e-ae91-d595f2f75867.filesusr.com/ugd/0af078_498ae21e3b7c432abbe0fc6e829d57ec.pdf?index=true
    • https://dc6b22d1-fd3c-476a-b8f1-b0505981f591.filesusr.com/ugd/ab5adf_bc02b9905dd344298c72c130197fb6d8.pdf?index=true
    • https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_644cec1815cc4c00bc68e261c753a5f2.pdf?index=true
    • https://b1b0174c-961c-4936-87f6-765e1132391e.filesusr.com/ugd/6cf804_ff45bac497044b089a82e13be12653ac.pdf?index=true
    • http://nozozuwovore.atwebpages.com/jolly_grammar_book_4.pdf
    • http://nejesezape.myartsonline.com/65253022883.pdf
    • https://ef733714-782c-48ea-8991-1bc0bf0c95f2.filesusr.com/ugd/ad2ade_0b37d4ee53494525971753b35453e8db.pdf?index=true
    • http://gurabagoderes.atwebpages.com/42881741840.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000125b7.bin
8be9858b8d5898de2d8fae035194bc69badfa20c292776314dd55711fb632a8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x125B7 5268 bytes
font_01_sfnt_off000137ba.bin
1489dc111d3d23a32373ce40a008e1336681b06bf8850baa2669c9e647669d02
pdf-font-stream PDF embedded font (sfnt) at offset 0x137BA 11068 bytes