Malicious PDF — malware analysis report

Static analysis result for SHA-256 2eba00b19665135e…

MALICIOUS

PDF

77.4 KB Created: 2021-04-28 03:14:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a2d8b661dc6fd2c417fb9034dab21ee7 SHA-1: 21bb9f1634f391affa7d7a5568be230a97147eb1 SHA-256: 2eba00b19665135eccc3e126274b2e0f182cea7aa7ad983785f8a0489825b9dc
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which point to potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' and 'PDF_URI' heuristics. The ML classifier and ClamAV detection strongly suggest malicious intent, likely for phishing or distributing further malware. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a lure to external malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=what+is+storage+in+records+management+definition
    • http://petajofap.22web.org/the_fish_marianne_moore.pdf
    • https://cdn.sqhk.co/kidurukazag/7jaf6ii/road_racing_cycle_helmets.pdf
    • https://jukonejidar.weebly.com/uploads/1/3/4/8/134876273/331232.pdf
    • https://cdn.sqhk.co/pemejurove/YjgRIih/kedavuxenir.pdf
    • https://wamurereleveti.weebly.com/uploads/1/3/5/3/135392703/wogojunupolinawog.pdf
    • https://cdn.sqhk.co/madeparev/BOjdYY5/dopejiweberar.pdf
    • https://cdn.sqhk.co/pixazizaze/0tWgjKX/dwyane_wade_son_age.pdf
    • https://cdn.sqhk.co/senuziker/fINPgi8/zakoj.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c763ec83-83d2-4fcc-88c3-336d59d59430/how_many_giants_in_the_bible.pdf
    • https://uploads.strikinglycdn.com/files/0fbb6ef7-c27c-410b-81fa-420c0adf94d0/what_are_the_5_basic_parts_of_a_computer_programming.pdf
    • https://s3.amazonaws.com/bojafazes/jabedewiditirel.pdf
    • https://uploads.strikinglycdn.com/files/176eb11e-8b6a-448f-b14b-2ce3f4c79a5c/what_is_the_meaning_of_capitalized_value_in_accounting.pdf
    • http://ninijoziwedef.rf.gd/carolyn_keene_nancy_drew_books.pdf
    • http://niwarapa.epizy.com/50214774009.pdf
    • https://uploads.strikinglycdn.com/files/fc579c00-77cf-47e9-8e66-c8123d7de458/encyclopedia_of_freemasonry_1917.pdf
    • https://uploads.strikinglycdn.com/files/abc2a6ff-e760-4137-839d-01c2305ece94/honeywell_electronic_air_cleaner_f50f1065_manual.pdf
    • http://rorizupoduvu.epizy.com/staff_appraisal_sample_report.pdf
    • https://s3.amazonaws.com/bajapovogam/applied_psychology_books.pdf
    • http://difugarulid.epizy.com/decursive_addon_guide.pdf
    • http://bikumekomem.epizy.com/kesuna.pdf
    • https://s3.amazonaws.com/sajatesawodiji/phrasal_verbs_meaning_in_hindi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f310.bin
b7e31681a603401102825afb3386cea81fbb769e3a71a5b019d0c9130b2dce3f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF310 5416 bytes
font_01_sfnt_off0001055d.bin
a9050efa5aa04b3ce878ecdf4160eb4e1376565fe19fe8d345559243287914dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1055D 10240 bytes