Malicious PDF — malware analysis report

Static analysis result for SHA-256 19cfc4c4ec638a22…

MALICIOUS

PDF

75.6 KB Created: 2021-03-30 13:35:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-25
MD5: 74d6a692bf3cd1939316daf4f4c9098a SHA-1: 233fb1ac0fa54d67b2027fbd9848ac885ef213af SHA-256: 19cfc4c4ec638a22007b0565ab400a1a76b0c978e274bf4692955ed1f3959d72
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/aws?utm_term=4+pics+1+word+8+letters+dog+with+binoculars PDF link annotation
    • https://cdn-cms.f-static.net/uploads/4401971/normal_5fdabd0e37972.pdfIn PDF document text
    • http://bevurib.22web.org/crazy_frog_ding_ding_mp4.pdfIn PDF document text
    • https://vebipebetas.weebly.com/uploads/1/3/4/0/134012388/resanugiwabiwu-fofuniso-wemigativoleke.pdfIn PDF document text
    • http://mebesovinu.22web.org/synergies_mod_guide.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366302/normal_602cfa88f0fa6.pdfIn PDF document text
    • https://gibawimeviz.weebly.com/uploads/1/3/5/3/135348906/72458.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/punagilelabon/wanabozu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/98fa91ac-471c-43ae-b35a-2895fb0cf6b9/40046516756.pdfIn PDF document text
    • https://s3.amazonaws.com/kovezux/how_much_does_newsmax_cost.pdfIn PDF document text
    • https://s3.amazonaws.com/jajuzasalikirut/how_to_do_emdr_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e06ade65-3c06-4b3b-ab0a-495289164091/joe_turners_come_and_gone_summary.pdfIn PDF document text
    • https://s3.amazonaws.com/mubefula/the_hack_driver_ncert_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/jofunozuzof/61985228756.pdfIn PDF document text
    • http://biwufedizew.rf.gd/john_coltrane_-_my_favorite_things_1961_full_album.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0772e1e6-484a-4471-860e-cb51f945f47a/kiruputizukuvaz.pdfIn PDF document text
    • http://bikutuvuxaxixo.epizy.com/fusionner_plusieurs_fichiers_en_un.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c5feed0c-2387-4540-834b-b31283e48c3b/how_to_replace_garmin_s2_battery.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ddd42972-d43d-431a-9db8-b71914b1e973/how_businesses_use_social_media_for_marketing.pdfIn PDF document text
    • https://s3.amazonaws.com/vipinib/g-shock_gw-9400-1ber_watch.pdfIn PDF document text
    • https://s3.amazonaws.com/farokof/honda_accord_2019_sport_manual.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e886.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE886 5804 bytes
SHA-256: 791709f2726675c2003b713b6cca05ca79f9b1b6f86f8c66a1a87dc8ff3212c4
font_01_sfnt_off0000fc54.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFC54 10800 bytes
SHA-256: 5237fc6726e3ab712145ce8b29f67b02586ffe6be1fb0e7099150dc2bb828700