Malicious PDF — malware analysis report

Static analysis result for SHA-256 295773b674d063dc…

MALICIOUS

PDF

85.5 KB Created: 2021-03-15 16:00:45 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 990d17af2175bc685f3a90e974bc9cf6 SHA-1: 37ff4cf8e439b9b5f8cd369e73daed65b5796035 SHA-256: 295773b674d063dc2734fa7486ed4d2e97a679055cd155a99bf6c1dfbe548014
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing or trojan threat. It contains a mass of external links, suggesting a link farm or a method to distribute further malicious content. The document body is heavily obfuscated and appears to be junk data, likely to mask the malicious intent of the embedded links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/award?keyword=acta+constitutiva+sociedad+anonima+pdf
    • http://timelessdecorum.com/basf_full_form_in_studyai3vq.pdf
    • http://makedctl.site/sevazolitatujasivuwdfv1s.pdf
    • https://cdn.sqhk.co/nobutowug/kjiVhbE/lynx_fortnite_skin_costume.pdf
    • https://tufelonidozuwux.weebly.com/uploads/1/3/2/6/132681512/bijoxa.pdf
    • http://mon-cmso.best/nietzsche_for_dummiesbkh3g.pdf
    • https://cdn.sqhk.co/wodelaganav/hhQgf9O/joxaker.pdf
    • https://cdn.sqhk.co/nejijilo/mN9Tiak/wakurubiwazugufupejarew.pdf
    • https://tokemenar.weebly.com/uploads/1/3/4/3/134337898/xujezatukozirekirabu.pdf
    • http://pixell.store/osmosis_problems_worksheet_answerss01d3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://nobudusoselazo.epizy.com/blessing_of_the_raven_queen_5e.pdf
    • https://e432c3f7-acc0-403b-bc7f-1b8c16782643.filesusr.com/ugd/6a4899_924b9ce818824f0dadc90ee6b00a9abc.pdf?index=true
    • https://02664c88-84e5-42fa-aae3-682d3a0d4328.filesusr.com/ugd/39d081_984289330a4d490ab84f77d02108b11d.pdf?index=true
    • https://9c789f27-b70c-4c9d-9e83-211ee8f99b38.filesusr.com/ugd/bdeb4c_63b4dcc0bbbc406b88e6018199f6e771.pdf?index=true
    • http://jafimogapevov.rf.gd/chrome_plugin_to_video_from_website.pdf
    • https://s3.amazonaws.com/nevovumowa/cube_and_cube_roots_worksheets.pdf
    • https://s3.amazonaws.com/zagubip/attach_screenshot_in_extent_report.pdf
    • https://s3.amazonaws.com/tiduro/genie_pro_screw_drive.pdf
    • https://fd0ef26f-7b8f-4c91-b3b2-19f7ec93487a.filesusr.com/ugd/4174bf_5080933d0d5e474bb23a2712e38c19d0.pdf?index=true
    • http://jeruzofifisamen.rf.gd/archero_abilities_guide.pdf
    • https://s3.amazonaws.com/baxadelefofibuz/esl_food_and_drink_worksheets.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011021.bin
3495bfb9171d339c69e225028b5ae05dd85a146d69c17bda075a723ffe88b861
pdf-font-stream PDF embedded font (sfnt) at offset 0x11021 5224 bytes
font_01_sfnt_off000121e2.bin
308cf9893b6a7a0abaae730dd9b45da292ed6f76274b188d38f0ceb71a557d5b
pdf-font-stream PDF embedded font (sfnt) at offset 0x121E2 11672 bytes