Malicious PDF — malware analysis report

Static analysis result for SHA-256 2de4e6bb31c57e39…

MALICIOUS

PDF

129.4 KB Created: 2021-04-06 08:01:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-10
MD5: 32de078b28732dad52616a6f90a7459f SHA-1: fab808c24c03e4661387334dfa7363eb7aaf80d6 SHA-256: 2de4e6bb31c57e39cde1ef548aa1d59ce85829ff1e27d82b2453f956750ee1ab
214 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a large number of embedded links, with several pointing to known malicious redirectors or link farms. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. No scripts were extracted, and the document body was heavily obfuscated, preventing a more detailed analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9601

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/123?utm_term=dna+model+worksheet+answers In PDF document text
    • http://libosuwobeg.iblogger.org/sevizixesa.pdfIn PDF document text
    • http://pevojatinolotej.22web.org/kurtulu_sava_cepheleri_zet.pdfIn PDF document text
    • http://wegansit.space/asus_xonar_dx_pcie_7.1_sound_cardgs1vg.pdfIn PDF document text
    • http://webmastervlad.ru/nabevsqcym.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369779/normal_5fe69de0c70f5.pdfIn PDF document text
    • http://indonesia2health.online/f1_ps_game8t204.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4416305/normal_603e8916cf589.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://2065f6f1-29fb-48ac-a230-4f4ab2d4b746.filesusr.com/ugd/b62953_c0ec6f5f0c2e4cdabcaaa5610c951590.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/ligole/wewil.pdfIn PDF document text
    • https://s3.amazonaws.com/migivewuwe/godavufejeva.pdfIn PDF document text
    • https://a2ae8793-a99f-480d-a3bc-849ef63d34f7.filesusr.com/ugd/cc207a_6f444e1f4c944faf876a044afac937d5.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/jodabiladezot/wemigunenewumomizum.pdfIn PDF document text
    • https://bc5ba30c-e427-49eb-abc4-9677f18f04c1.filesusr.com/ugd/bcd086_c43cab78e9a24bd7bf65cd5ed5d8bd50.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/benubapopikaj/43867085444.pdfIn PDF document text
    • https://s3.amazonaws.com/nagev/gta_sa_cheats_apk_free.pdfIn PDF document text
    • https://s3.amazonaws.com/bivanud/blood_bowl_2_teams_wiki.pdfIn PDF document text
    • https://69cf8a46-0d3d-4b71-8fd1-93df925da18e.filesusr.com/ugd/e4064d_6d0056bef6f14eccbb46c7fdcf26053a.pdf?index=trueIn PDF document text
    • https://e1d5fa5a-667c-4d22-bb72-2ec96b4ed0f7.filesusr.com/ugd/01f30d_b83fb58a696d4397a1c4acf695417894.pdf?index=trueIn PDF document text
    • http://gawasaxe.epizy.com/free_templates_html_css_javascript.pdfIn PDF document text
    • https://s3.amazonaws.com/kibavutibeved/comrade_in_america_songs.pdfIn PDF document text
    • https://s3.amazonaws.com/jigezilor/camedia_master_4._2_software.pdfIn PDF document text
    • http://nimetegukixiz.rf.gd/equation_of_the_line_standard_form_slope.pdfIn PDF document text
    • http://bomajada.epizy.com/practically_speaking.pdfIn PDF document text
    • https://s3.amazonaws.com/kovezux/95943871622.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off0001bfb2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1BFB2 17112 bytes
SHA-256: 612131580d98463c0e3de58c4467fea434006b50d32e05c1db43d1e60ba58055
font_00_sfnt_off0001492a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1492A 6732 bytes
SHA-256: fbb13df32eaf1b0116cf20a019158238f293aa978da79f3b1400f24ca458c804
font_01_sfnt_off000159dc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x159DC 4808 bytes
SHA-256: a82cab5a1ffae50e876c2a376ce3856c213c052c85bf2a3bdcb82fd79e9fc332
font_02_sfnt_off00016aac.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16AAC 4960 bytes
SHA-256: 699f66e6df61c3c0a6ec11ee644cd79296f6dfb0d9849abefd15150571e0e035
font_03_sfnt_off00017b68.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17B68 2080 bytes
SHA-256: 9c38eeba2c4096a63b9103ef52d0365e3ecba43721a167e87202f21563eb1f72
font_04_sfnt_off0001853a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1853A 18728 bytes
SHA-256: b0d8ba4a3583ace7b869f8a659da695c8df4b2b56795070d39faefa8e4486660
font_06_sfnt_off0001d85c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1D85C 4324 bytes
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
font_07_sfnt_off0001e61f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1E61F 6208 bytes
SHA-256: 8ae0463ef85505b025104a5aa901dcf45039f5c915eab4143501f0470c9be3b5