Malicious PDF — malware analysis report

Static analysis result for SHA-256 24810f5943bd9f81…

MALICIOUS

PDF

89.1 KB Created: 2021-04-06 07:57:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9bcf515a0b0586015e5a42b7344510ba SHA-1: eb0f810f63cd60605ec6af227b98579f341d4c15 SHA-256: 24810f5943bd9f8168c925d0f9b91d2e5b7ab4674010b8461a0c21f7d1941144
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for link farms or distributing malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as a phishing trojan. While no scripts were directly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/strik?utm_term=how+to+sync+samsung+tv+remote+with+dvd+player
    • https://cdn.sqhk.co/totafeta/8ghhEH9/loxelixara.pdf
    • http://lnstagramoriginal.com/tekken_3_pc_game__30mbid3jd.pdf
    • http://tublitalia.fun/how_to_properly_use_a_humidifierm7k0x.pdf
    • https://cdn-cms.f-static.net/uploads/4375070/normal_606b81dd87402.pdf
    • https://cdn.sqhk.co/rufazodaxu/1xNjbCe/jawedarobo.pdf
    • https://cdn-cms.f-static.net/uploads/4460966/normal_604d82779ec28.pdf
    • http://sokfresh.fun/vuvolokaxatagiq6.pdf
    • https://cdn-cms.f-static.net/uploads/4388614/normal_5fd9443f069af.pdf
    • https://cdn.sqhk.co/lisakopew/QBigfgj/robotics_notes_elite_gameplay.pdf
    • http://wdd13.ru/dekazokanetcyzm6.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://eb40363d-1d1f-4170-a897-f23f0f433116.filesusr.com/ugd/2a1429_250c53e0fcad4f9db60c6f1f28a9ff70.pdf?index=true
    • https://40e214c1-1950-44e8-a195-e2c6eeb23253.filesusr.com/ugd/a517f4_d16a8cbda7fa4d2ab5c1d74176e3750c.pdf?index=true
    • https://7a579b3f-ce96-4c66-abdc-991530493d29.filesusr.com/ugd/010c6b_0d8aeffc41ce4cb3a16a51aa04f6df5e.pdf?index=true
    • https://b64dd490-e5b9-492f-89ff-e398ecee904c.filesusr.com/ugd/5926b4_d7d1235015e64716a9695cce6c3acb3f.pdf?index=true
    • https://3c199e1c-ff83-4553-a351-db1e9419129c.filesusr.com/ugd/424a74_a335a80339804bfa93f13309167e9f37.pdf?index=true
    • https://7ef5d8b8-74ac-4e0a-b0a0-fa61ca6462a8.filesusr.com/ugd/23e9be_ca03cbd195f9420fb1d8a33299cdeafe.pdf?index=true
    • https://034b020c-baab-45d1-b3ff-c950d21f9178.filesusr.com/ugd/3c93bc_a70863c26d6a44418e09e6a0ba4fdd4c.pdf?index=true
    • https://937a8a2d-b41a-4163-aff8-eda6db263557.filesusr.com/ugd/21e6f2_b97a252ac3344ce6be0d8de0bb0d1dfb.pdf?index=true
    • https://3e80c8bf-0031-4ca1-bfa9-4484641fefed.filesusr.com/ugd/08103e_15b878bd6d7548048354b8242cba5a80.pdf?index=true
    • https://6d4cd3b7-91e9-43ac-92b9-205473f1e50d.filesusr.com/ugd/28146e_8736c5b539f340fd8784a7b80a9c8001.pdf?index=true
    • https://af4bb04d-41a2-413c-b691-ce0a46ff998d.filesusr.com/ugd/e677f8_ed966fbdb1e8444a9ecb5c453a19e5d6.pdf?index=true
    • https://681956c7-2c57-495f-b996-d04b50c745b0.filesusr.com/ugd/907d98_4ac4f62d08374fb3909355e69c1e0a95.pdf?index=true
    • https://acda325f-ee3b-40e4-882f-fabc489a6840.filesusr.com/ugd/23b3d3_4f9c8637c7b74515858b49f2b818a1c2.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fcb6.bin
b3dfb2f2c41da7350fc3755141d2fd0ea5796bb125df25fec831093623ff73df
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCB6 2900 bytes
font_01_sfnt_off000106f9.bin
b629bd09a50439fdd9e71d06f6fe49881243f48b9932321ce569fc414e449190
pdf-font-stream PDF embedded font (sfnt) at offset 0x106F9 5700 bytes
font_02_sfnt_off00011a4c.bin
2c0f2cd1655dcaf697372d0a0df1da462d172d23856f34e1e8f2d3f52c350b73
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A4C 11084 bytes
font_03_sfnt_off00014041.bin
9a4cbfef1d361b49d4faaeef6ced77ef0fd92f26152dd8eab1109b0e9abbc1b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x14041 16232 bytes