Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a622b319f3bcf53…

MALICIOUS

PDF

80.1 KB Created: 2021-03-15 16:31:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 632b8a8dafd8c9fc88b2cf412d59ce44 SHA-1: 7642459b27023f3648664373eb19c33af86c39a0 SHA-256: 2a622b319f3bcf53711b912135c261113e0fdc34cfca27028149f87878ab12df
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, many of which are disguised as SEO-friendly content, suggesting a link farm designed to distribute malware or phishing content. The primary URL points to a resource related to game hacks, indicating a lure to attract users to download potentially harmful files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=call+of+duty+mobile+hack+mod+apk+download
    • http://fesurowejo.mywebcommunity.org/journey_to_the_center_of_the_earth_full_movie_free_download_in_telugu.pdf
    • http://tenipimutav.mywebcommunity.org/capitalismo_gore_libro.pdf
    • http://rusadezebep.mygamesonline.org/20085204193.pdf
    • http://fotonagosuslugi-01.space/symantec_dlp_agent_guide3ejoa.pdf
    • https://mufaguzesevulet.weebly.com/uploads/1/3/2/8/132814956/zodekikaluku.pdf
    • http://wspring.space/46299251985tgqb9.pdf
    • http://remont-kholodilnikov.website/19100049283rpu93.pdf
    • http://dikegebe.mygamesonline.org/biological_science_let_reviewer_2020.pdf
    • https://mosivupidener.weebly.com/uploads/1/3/1/6/131637589/7284784.pdf
    • https://doruvovet.weebly.com/uploads/1/3/2/7/132740873/7774576.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/wewuxuviwar/98717539288.pdf
    • https://s3.amazonaws.com/dekogamik/nugipomoriba.pdf
    • https://uploads.strikinglycdn.com/files/6eaa6dc5-4218-434e-a9de-361f27f67c9d/galimepelaf.pdf
    • http://mojozore.myartsonline.com/putigifitapib.pdf
    • https://uploads.strikinglycdn.com/files/99e9c875-155f-4ac0-b796-70ee26a959ac/83650382633.pdf
    • https://uploads.strikinglycdn.com/files/7514a1f3-192d-4a95-a7d0-32df8645211b/cuales_son_los_tipos_de_comunidades_educativas.pdf
    • https://uploads.strikinglycdn.com/files/e82b359c-67a6-4a16-b286-55798c3455f9/recaro_performance_sport_combination_harness_to_booster_car_seat.pdf
    • https://uploads.strikinglycdn.com/files/d39f4dfb-c916-48a8-9c6e-d2bffbde3a26/whats_the_difference_between_keurig_mini_and_mini_plus.pdf
    • https://s3.amazonaws.com/baritexovopa/xamexeselimexafedix.pdf
    • https://s3.amazonaws.com/zufojadibi/cheat_engine_7._9.pdf
    • https://uploads.strikinglycdn.com/files/94bd433c-2b78-4268-ad50-4daa4a0d65b0/57508210791.pdf
    • https://s3.amazonaws.com/fukezavazuj/nedozix.pdf
    • https://uploads.strikinglycdn.com/files/92303501-3e9f-40ee-a89f-23fd1be2fb68/26567485842.pdf
    • https://uploads.strikinglycdn.com/files/5c3ce116-8fb0-44cf-894e-0390ba14e2ae/how_to_clean_with_microfiber_mop.pdf
    • https://uploads.strikinglycdn.com/files/26f85808-dbfc-4cad-ba70-bc117ac5b05e/how_to_overcome_ocd_naturally.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fae7.bin
bf53baa060b17e0d946c3a413ccf3865715d26cea77142687226b7917160bd0e
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAE7 5424 bytes
font_01_sfnt_off00010d4f.bin
50dcb29e1cc7f7b45f01de098cc6c3d05ed028da715d24d606dbd25aedcbdc1c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D4F 10920 bytes