Malicious PDF — malware analysis report

Static analysis result for SHA-256 226ee102f8764cad…

MALICIOUS

PDF

76.5 KB Created: 2021-05-19 19:58:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bcb9df6eb148517bc8850cd42486a45d SHA-1: dcba66e22714e7171fcd51ee10d1689df6d256d3 SHA-256: 226ee102f8764cada16f6cfd3a95b0d30f54b7eccd342ad6f205d464f5053f57
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous links to external websites, many of which appear to be part of a link farm designed to attract users searching for pirated movie downloads. The presence of a critical heuristic firing for PDF_SEO_LINK_FARM and a high ML score indicates a strong likelihood of malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to malicious content or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=arunachalam+movie+download+tamilrockers+tv
    • https://bezofaxifi.weebly.com/uploads/1/3/1/6/131606652/f4f5b08892b4e08.pdf
    • https://cdn-cms.f-static.net/uploads/4415544/normal_601024c528c0e.pdf
    • https://cdn-cms.f-static.net/uploads/4366036/normal_601410e826ac6.pdf
    • https://giximanuv.weebly.com/uploads/1/3/4/5/134526051/5bce779.pdf
    • https://dizakevusarebiz.weebly.com/uploads/1/3/4/5/134581037/d1da0fd1.pdf
    • https://ladipepisosixas.weebly.com/uploads/1/3/4/8/134898905/nesusigewuze.pdf
    • https://gukilebulasule.weebly.com/uploads/1/3/2/6/132682884/zomoko-belujanikezipi-dejotifirowaf-gixuwavutubax.pdf
    • https://tanuroxej.weebly.com/uploads/1/3/4/1/134131309/siredutavoz-xenawewugeg.pdf
    • https://cdn-cms.f-static.net/uploads/4462354/normal_601dc982c4abe.pdf
    • https://mepokebifonamos.weebly.com/uploads/1/3/4/0/134096039/lanafuj.pdf
    • https://bamigabimav.weebly.com/uploads/1/3/1/6/131636977/rujafakazuvovefe.pdf
    • https://badevejolaf.weebly.com/uploads/1/3/4/8/134867981/romojuvegasedi.pdf
    • https://ronifevux.weebly.com/uploads/1/3/4/7/134737402/c107d07.pdf
    • https://static.s123-cdn-static.com/uploads/4404285/normal_5ff416a1c889d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/sojebelevenex/bruce_lee_quotes.pdf
    • https://s3.amazonaws.com/votubukaxogilix/lixanotobapurubalenik.pdf
    • https://s3.amazonaws.com/fekazudabo/dekigujexijafiworawibode.pdf
    • https://uploads.strikinglycdn.com/files/72bcb562-0365-49a9-b5ba-6a7b2384bd79/how_do_i_program_my_vtech_cordless_phone_to_the_base.pdf
    • https://uploads.strikinglycdn.com/files/8248e917-01d4-4134-8c50-c59c0426ccb5/best_interview_questions_to_ask_candidates_2020.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eeb0.bin
7ea080e8dcd7922a86f1cecfe126d56425cdba0c16364d27f1c264b6db549f65
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEB0 5384 bytes
font_01_sfnt_off000100e6.bin
06236feb207976c4e9363f6663f1e1426ad1e0fd524219bf22dab06fd1c3e44e
pdf-font-stream PDF embedded font (sfnt) at offset 0x100E6 10564 bytes