Malicious PDF — malware analysis report

Static analysis result for SHA-256 2db60d254f833ab8…

MALICIOUS

PDF

79.4 KB Created: 2021-05-02 03:58:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7e6263c00986049ed1ccf3cb821e7b92 SHA-1: 298a63431ad0868e70e384a850bd8c4f632a4b76 SHA-256: 2db60d254f833ab81d1f4b73bbaa252b5b78e544fb12b32547206943015f746b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as a phishing trojan. The primary malicious activity observed is the embedding of a large number of external links, suggesting a link farm or phishing campaign. The document body contains garbled text and metadata, indicating it is not intended for legitimate user interaction.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=is+the+woman+in+the+window+on+netflix
    • https://cdn.sqhk.co/molavagew/bc472YV/dipipawunijabasexotipijo.pdf
    • https://cdn.sqhk.co/totarujined/id38Jgj/pak_army_song_hd_video_free.pdf
    • https://cdn.sqhk.co/ximegawaso/gheihgg/49859227561.pdf
    • https://cdn.sqhk.co/kuwusemob/CeW8Yie/rimidozilitimonofitiga.pdf
    • https://cdn.sqhk.co/kasavakujosi/ZeGEcij/7281349355.pdf
    • https://cdn.sqhk.co/fifotadog/hhfijyy/marooned_with_ed_stafford_norway_watch_online.pdf
    • https://cdn.sqhk.co/vimerokil/h7ggyjf/farm_together_starry_harvest.pdf
    • https://cdn.sqhk.co/letinumi/y1jh9ym/xuzexukutewasenedonelujer.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://ee67c5b3-b4d3-4257-b425-af55881d3a68.filesusr.com/ugd/c60da7_672933e651d0493e9f7628cd802da8c4.pdf?index=true
    • https://4a39c6c9-989b-4d11-b2d8-cc0becc7f193.filesusr.com/ugd/ef0078_2bfab75ecb63439f9db93c4b1fae7de8.pdf?index=true
    • https://9db8f275-5044-409a-aa1b-3306d9dda9bd.filesusr.com/ugd/361f4b_c113cdd32f4e4bdf8764b2d630ee1c36.pdf?index=true
    • https://2fe0a9f4-4d23-48c4-8711-d5fb25093877.filesusr.com/ugd/683a75_912b6b4bebc84c80b95986c222c7f9d2.pdf?index=true
    • https://ef2e072a-e8a2-4438-804d-cc750be2e2f6.filesusr.com/ugd/6a22cb_2ca68932ae8f4096a770bcd0fd3416ff.pdf?index=true
    • https://f3b8d348-8566-49c9-a9f8-a2c3b9e1bc8e.filesusr.com/ugd/f1c748_111cb5b41be54f38bf8ec91258b10296.pdf?index=true
    • https://a1359116-1358-4cde-afc5-3600b4bb50db.filesusr.com/ugd/3b0c81_93d0438fd7004a22be2b75ebbd4df01f.pdf?index=true
    • https://43a2ba88-5de9-465b-b95f-6a4d82f2d06e.filesusr.com/ugd/dcbeda_85aca6383a59464cb5b50dcb0eebaedb.pdf?index=true
    • https://9e6c4f0b-3406-4274-bf8a-5be7f948d240.filesusr.com/ugd/45c6ff_d160d2d0ce5e41e08af63b1314fc80a0.pdf?index=true
    • https://a0f1d9c0-ea46-4e0e-9383-d87711d3127f.filesusr.com/ugd/1e3fb7_d4e3c4b68d604aa294615f1ae7e22653.pdf?index=true
    • https://e2a3f85e-3ce8-4c76-99a2-e63219cad5ad.filesusr.com/ugd/473d25_28bcf1cac23f45e49783be14ae166fb4.pdf?index=true
    • https://737c154f-ca75-4484-807d-9d5c19d76377.filesusr.com/ugd/7e84b7_9514a051104c479c988f8f872e09070e.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e99f.bin
02f6658b925b8ecc1cf4ef3821714f7fad6e2a1fbc27a669ba872fb78960ac03
pdf-font-stream PDF embedded font (sfnt) at offset 0xE99F 5148 bytes
font_01_sfnt_off0000fb0a.bin
0cc38a9a6445cf96e8173114c460a4730a2602588055e9a0e82503a7a986b7b9
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB0A 3624 bytes
font_02_sfnt_off000109f3.bin
5a7286d4e0d05f4208944d60ebe20911deacd9645880cee5c6c4954954dfcb26
pdf-font-stream PDF embedded font (sfnt) at offset 0x109F3 11256 bytes