Malicious PDF — malware analysis report

Static analysis result for SHA-256 248150078494338a…

MALICIOUS

PDF

76.3 KB Created: 2021-03-09 09:09:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a246cae569ae1debf5f0a06872711ee0 SHA-1: 71362edb1beb9dfdddcf12cc035ded39eeee85ed SHA-256: 248150078494338a70168b3e488a4751f8fdd60506e16bb85fdbebec3b843748
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. The document contains a large number of embedded external links, many of which point to suspicious domains, suggesting a link farm or phishing attempt. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of malicious intent, likely related to spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=why+won%2527t+you+answer+me+lyrics
    • http://scm03.ru/20704862065aufh1.pdf
    • http://cheatyou.site/starting_strength_3rd_editioni48qu.pdf
    • http://jeruxawi.iblogger.org/anonytun_pro_apk_2017.pdf
    • http://3bureaureport.info/dna_structure_worksheet_answers54w2c.pdf
    • https://static.s123-cdn-static.com/uploads/4393762/normal_5fe50c80670e7.pdf
    • https://malugeko.weebly.com/uploads/1/3/1/6/131636988/6715459.pdf
    • https://jixejuterekafiw.weebly.com/uploads/1/3/4/5/134508928/00456cec.pdf
    • http://pijitirade.iblogger.org/can_android_iphone_apps.pdf
    • https://static.s123-cdn-static.com/uploads/4372384/normal_5fe36b6243815.pdf
    • http://help-business-media.com/hindustan_unilever_products_price_list_inj9gbx.pdf
    • https://cdn-cms.f-static.net/uploads/4475988/normal_60103dcf2e7b3.pdf
    • https://bomaripuxizidul.weebly.com/uploads/1/3/4/9/134901287/jaxexolog-fajirof.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/murudute/propiedades_del_acido_acetico.pdf
    • http://sodividupoz.epizy.com/how_to_use_suunto_d4i_dive_computer.pdf
    • https://s3.amazonaws.com/bejikefowu/avensis_2015_manual.pdf
    • https://s3.amazonaws.com/rimejiguvif/house_rent_agreement_format_in_english.pdf
    • https://s3.amazonaws.com/begijufadi/paxutinujozaviwasaze.pdf
    • https://s3.amazonaws.com/wudibirewuduto/24540259362.pdf
    • https://s3.amazonaws.com/marimejerebo/android_studio_emulator_cannot_connect_to_internet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eebd.bin
ccb235320460ac779f53520b6008757d77b49dd8460f8c904a1af3f85f465837
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEBD 5280 bytes
font_01_sfnt_off000100ab.bin
93b952f53d08e814de9c29ad75b080e62e603b3b87eb06f2bdb80f255d9b8e71
pdf-font-stream PDF embedded font (sfnt) at offset 0x100AB 10408 bytes