Malicious PDF — malware analysis report

Static analysis result for SHA-256 2190fd22394830ba…

MALICIOUS

PDF

90.7 KB Created: 2021-03-15 07:34:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e43bcdeb898e56f259fd4e44301ddff8 SHA-1: 201820c8c19e239788d2f5c118905514badc4d38 SHA-256: 2190fd22394830ba6197fc9fa33a68521530b137df04332b7a6720ac482cd795
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for link farms and phishing lures, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The ClamAV detection and ML classifier strongly suggest malicious intent, specifically identified as 'Pdf.Phishing.Trojan'. The embedded URLs are likely used to redirect users to malicious sites for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=lineas+horizontales+y+verticales+dibujo+tecnico
    • https://cdn.sqhk.co/midipijikami/jhidGhc/90472304159.pdf
    • https://cdn.sqhk.co/wenewojufaj/Nhdv0he/mobile_kitchen_cabinet_showroom.pdf
    • https://cdn.sqhk.co/jifedibodo/ih9jjSL/lily_s_garden_ad_pregnant_test.pdf
    • https://cdn.sqhk.co/febowozefu/gjf1gjx/free_high_school_diploma_template.pdf
    • https://static.s123-cdn-static.com/uploads/4392649/normal_5fcc0d269bbff.pdf
    • https://cdn-cms.f-static.net/uploads/4454973/normal_6034715faa811.pdf
    • https://cdn.sqhk.co/gixedomawa/aWkFVs1/66265865974.pdf
    • https://cdn-cms.f-static.net/uploads/4375342/normal_5fd77f28b38c5.pdf
    • https://cdn.sqhk.co/kerodamajop/vgfyvNr/3d_printed_tennis_ball_launcher.pdf
    • https://cdn-cms.f-static.net/uploads/4449424/normal_603514f7445c4.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://relogevavikidid.epizy.com/gonuvipesivi.pdf
    • http://janalusexisowa.epizy.com/flyers_template_photoshop.pdf
    • https://s3.amazonaws.com/piwanisaj/13492337674.pdf
    • https://s3.amazonaws.com/pujinit/mupegujes.pdf
    • https://s3.amazonaws.com/jinabom/bamitusokaxekekabeto.pdf
    • https://0fdd9f25-8366-4660-9463-376fd915ad39.filesusr.com/ugd/c16cf9_c58a0a4a26674c3fad6543182fc79f4b.pdf?index=true
    • http://xevivalekivo.epizy.com/zitafowamuvutege.pdf
    • https://05e27880-d5e1-4d3d-8428-ba943e9300bc.filesusr.com/ugd/b56239_ce3427b17ea9437e83d93b8bcf4c584c.pdf?index=true
    • http://dogugamegomijit.rf.gd/figokifuzadatiri.pdf
    • http://kisopazagutux.rf.gd/62933302979.pdf
    • https://s3.amazonaws.com/degisapemifa/xenilononafi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012098.bin
e47cb91788bedcf416a4df66bb6ade1cf6a719390c6935f5796ae968b05d71fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x12098 5396 bytes
font_01_sfnt_off00013302.bin
94cfb089a456a75a6356c59754b77eefa75e6d3c9deadcdf9508dd75a6cfc383
pdf-font-stream PDF embedded font (sfnt) at offset 0x13302 12548 bytes