Malicious PDF — malware analysis report

Static analysis result for SHA-256 253a5eb121779920…

MALICIOUS

PDF

79.9 KB Created: 2021-03-23 18:42:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 01afbacf6b5b0ec035d637b5fd9d53b1 SHA-1: 957743c3e8933f51dd711ac5f248809e26397434 SHA-256: 253a5eb121779920041b69023cc1cb9254f98ae760642c8bf0b69cd0d08eb02d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The 'ML_NYX_PDF_MALICIOUS' and 'CLAMAV_DETECTION' heuristics confirm the malicious nature of the file. The document body, though heavily obfuscated, suggests a lure related to a 'car boot sale poster template', which is likely a pretext to direct users to these external URLs for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=car+boot+sale+poster+template
    • https://digagewopaloz.weebly.com/uploads/1/3/4/6/134634746/8174968.pdf
    • http://senteber.site/acg_guidelines_pancreatitiszzt3u.pdf
    • https://regezubigif.weebly.com/uploads/1/3/5/3/135320660/387989.pdf
    • http://soldatskaya6.ru/what_are_the_new_covid_restrictions_for_victoria8s6oi.pdf
    • http://hook-up.fun/93370725251ao0fu.pdf
    • https://cdn.sqhk.co/dukosisevu/hbbsieN/pesujazofezizowodigaxiwi.pdf
    • https://cdn.sqhk.co/nemoludajedu/wlqjfO1/ruzovus.pdf
    • https://nadaxobolimige.weebly.com/uploads/1/3/4/3/134365666/e7f85f9.pdf
    • http://lozomaneje.getenjoyment.net/the_kiss_quotient_book_download.pdf
    • http://fishland.store/21468502475x1qjb.pdf
    • http://erse.xyz/69056048075bku7g.pdf
    • https://ximesadi.weebly.com/uploads/1/3/0/9/130969353/7654889.pdf
    • https://zitavuzan.weebly.com/uploads/1/3/1/3/131379524/a84aa33cbd8cd.pdf
    • https://cdn.sqhk.co/fusajovogi/hiijngc/best_picture_quality_camera_app.pdf
    • http://instapriz365.online/fenodo1433g.pdf
    • http://sitonuba.mypressonline.com/12074718310.pdf
    • http://goodxday.xyz/xumetohg53o.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://masemipeba.myartsonline.com/corel_draw_x5_all_shortcut_keys.pdf
    • https://493f174a-a540-412c-bacb-e5b7b26cbfcf.filesusr.com/ugd/95bb70_d15d839757fb4cd99c5033eb8974f2c2.pdf?index=true
    • http://rikuworubit.myartsonline.com/international_phonetic_alphabet_chart_with_examples.pdf
    • https://810dce77-56ab-4324-823a-3549757f4eab.filesusr.com/ugd/1fad07_e53f86fe6d4e432caed8d5679af0386e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000faad.bin
e26382b58b470f94dc19358d665646f1eb0a4a90b5cd12691a81883caa07989b
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAAD 5012 bytes
font_01_sfnt_off00010b96.bin
df9e9904c4e59cf0e40d6eecba8c8b6ee58ab8c573ef19068aae7924c964c147
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B96 10976 bytes