Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a2243b670cf7e94…

MALICIOUS

PDF

81.6 KB Created: 2021-06-06 07:06:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 78edaaad0efb37d6f69c06a66666b584 SHA-1: 9e6e7dbc7c91b5da76b6edc3e3f0cb69f776d400 SHA-256: 2a2243b670cf7e943abdf52ef1f606d2ba5c915801447e714070803353cb4262
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics as malicious, including ClamAV detection for 'Pdf.Phishing.Trojan'. The PDF contains a large number of external links, suggesting it is part of an SEO spam or link farm operation. The primary URL, 'https://oniceh.ru/wb?keyword=o%20que%20fazer%20quando%20as%20fezes%20n%C3%A3o%20saem', is likely used to direct users to malicious content or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://oniceh.ru/wb?keyword=o%20que%20fazer%20quando%20as%20fezes%20n%C3%A3o%20saem
    • https://static.s123-cdn-static-d.com/uploads/4374682/normal_60b54754435e4.pdf
    • https://zisetilu.weebly.com/uploads/1/3/1/3/131382786/vemaxavokibal.pdf
    • https://murudogukezopo.weebly.com/uploads/1/3/4/3/134320821/siledasi.pdf
    • https://static.s123-cdn-static.com/uploads/4489850/normal_5ffccd5e5209c.pdf
    • https://static.s123-cdn-static.com/uploads/4477629/normal_5fe4f1857dd46.pdf
    • https://cdn-cms.f-static.net/uploads/4387061/normal_6066fb3feec0a.pdf
    • https://cdn-cms.f-static.net/uploads/4474223/normal_603b71aa6ead2.pdf
    • https://pakimisubimoge.weebly.com/uploads/1/3/0/7/130776027/dasejotitadivopi.pdf
    • https://cdn-cms.f-static.net/uploads/4365600/normal_603be61755ac8.pdf
    • https://static.s123-cdn-static.com/uploads/4417406/normal_5fe18296d02dc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/1abf4198-b48b-4e96-a305-5488c0bf5101/vurajapupadasiwiruwaxij.pdf
    • https://uploads.strikinglycdn.com/files/1a960bfc-35da-44f5-9810-3c8bd9a7abe5/6250719737.pdf
    • https://uploads.strikinglycdn.com/files/4de30d6e-8e51-4e53-a9fb-a1633f21a9c8/tighten_manual_eject_screw_ps4_slim.pdf
    • https://uploads.strikinglycdn.com/files/1d09e451-79e6-4683-b000-cd2d72a69b7f/rebekoniz.pdf
    • https://uploads.strikinglycdn.com/files/c75429e8-14eb-49a5-ae06-6b6c54ef2e65/nitotiduzerezewexu.pdf
    • https://uploads.strikinglycdn.com/files/a008b1c9-be57-4498-9c21-35342e150918/the_sum_of_the_interior_angles_of_a_polygon_is_1440._how_many_sides_does_the_polygon_have.pdf
    • https://uploads.strikinglycdn.com/files/8bbaede2-f4e0-4e69-8f20-c2046a30f0f6/guerra_de_guerrillas_significado_diccionario.pdf
    • https://uploads.strikinglycdn.com/files/521fac79-c9a8-4459-8abd-4a4fd5e282d1/what_movies_are_coming_to_netflix_australia.pdf
    • https://uploads.strikinglycdn.com/files/354cd30d-fdf2-42be-9bb0-dd6cf3f18690/senuvev.pdf
    • https://uploads.strikinglycdn.com/files/5142a8ba-c1a3-4521-ae4c-d6e47b752428/chapter_26_section_1_origins_of_the_cold_war_worksheet_answers.pdf
    • https://uploads.strikinglycdn.com/files/30877439-08eb-41b6-92da-edcbe430ce94/mikefuxulupibodazupapit.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eec7.bin
5f653d70acf651418bfcbd30fd902ed9fc1c6b7f9ab858824089c95a9e9afe42
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEC7 5296 bytes
font_01_sfnt_off0001001c.bin
9c9d4b36eaf12896abbd7a3bb6f4f5758e11844f203dde4d6286c67e59ab40e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1001C 13272 bytes
font_02_sfnt_off0001290b.bin
8405bb6ca9a6fb718a2e910e1cdde4d74ac2122cab0061dc5f772322db9c7ccd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1290B 4324 bytes