Malicious PDF — malware analysis report

Static analysis result for SHA-256 19cd8832152d3de0…

MALICIOUS

PDF

77.8 KB Created: 2021-04-02 15:15:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0206c13c085707bd97097820643482d7 SHA-1: 5b9caa5e4aa76c767c0276f305f731f680eb83fe SHA-256: 19cd8832152d3de01302d7f149813b3634515cfff818bf5c64055b8f9f44aaa4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, a technique often used for SEO manipulation or to redirect users to malicious sites. One of the primary external URIs points to a suspicious domain, suggesting a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/award?keyword=advantages+of+a+franchise+pdf
    • https://cdn-cms.f-static.net/uploads/4476930/normal_5fe8176075645.pdf
    • https://cdn-cms.f-static.net/uploads/4368237/normal_604d17dd197d0.pdf
    • https://pavadugubuwab.weebly.com/uploads/1/3/4/3/134309483/kivuzirapovedozuki.pdf
    • https://cdn-cms.f-static.net/uploads/4484610/normal_605798eecec96.pdf
    • https://cdn-cms.f-static.net/uploads/4384644/normal_60366ab18dbb1.pdf
    • https://cdn-cms.f-static.net/uploads/4376372/normal_603548870bb60.pdf
    • https://static.s123-cdn-static.com/uploads/4452193/normal_5ff31ebc87876.pdf
    • https://cdn-cms.f-static.net/uploads/4391305/normal_5fd989cbb8b50.pdf
    • https://static.s123-cdn-static.com/uploads/4470402/normal_6006339eee602.pdf
    • https://turexebino.weebly.com/uploads/1/3/4/2/134265835/b9d5f1acb.pdf
    • https://cdn-cms.f-static.net/uploads/4392462/normal_603f9427959a6.pdf
    • https://cdn-cms.f-static.net/uploads/4502567/normal_603c394de4760.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/02fd648f-8e2b-4ad2-bfef-826541b5876e/how_much_are_iphone_7_screen_repairs.pdf
    • https://08c3cc13-1ce0-4add-927e-a3aed263473e.filesusr.com/ugd/ccf397_a1501be432374d37b34912c520aa6fb2.pdf?index=true
    • https://s3.amazonaws.com/kisagoz/99534774491.pdf
    • https://s3.amazonaws.com/voxulija/fairy_fencer_f_dark_advent_trophy_guide.pdf
    • https://s3.amazonaws.com/nisiwanolom/structure_agency_theory.pdf
    • https://3cde87c3-25ab-478b-b58d-ba072f1c7540.filesusr.com/ugd/255d97_4c649741978e49dea1ccf64ad2030e65.pdf?index=true
    • https://6e345194-e688-4037-aa24-2ff230a16836.filesusr.com/ugd/ce9fe1_2e23a8f02a22426e9c27c9f797e4cf43.pdf?index=true
    • https://uploads.strikinglycdn.com/files/94ffd49c-01ba-4ee1-9154-7c7c87cae7e5/figivatofimew.pdf
    • https://uploads.strikinglycdn.com/files/c9cdafc5-0f12-4dfd-b90a-66f558bd8965/texivegovejujovebuwupib.pdf
    • https://s3.amazonaws.com/dazuxujepov/18367557785.pdf
    • https://uploads.strikinglycdn.com/files/55d6e567-4b0d-44ae-a62b-8a966d71e7b5/gevozukasitibapeseja.pdf
    • https://89d37d93-eaf9-4fc7-8d5e-07438b8f18e7.filesusr.com/ugd/e80f4c_e8bccac3390e4d04926d8fc0cf517e66.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f2a9.bin
56cab1aae65524f53d3139f99e66013aa9dc8dddc8e4948508b7492520e3a0d8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF2A9 5436 bytes
font_01_sfnt_off00010530.bin
2e9af94d9d8464f4a93abdbe0a8e9e56c141c4eb4e48a924dcac18ab5b9943ea
pdf-font-stream PDF embedded font (sfnt) at offset 0x10530 10808 bytes