Malicious PDF — malware analysis report

Static analysis result for SHA-256 30764a016bba26dc…

MALICIOUS

PDF

82.8 KB Created: 2021-03-15 16:03:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a3292b8b0520bb42265e33437e457948 SHA-1: 6adcc1459f0e5e6cac40e92fee5dc5068978eacd SHA-256: 30764a016bba26dcd3fbb1053d72ef6a079bbafd4bf384ca418ceef091f1d7ed
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF document that contains numerous embedded URLs, many of which point to disposable domains and are flagged as part of a link farm. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically phishing. The document body, though heavily obfuscated, appears to be a lure related to 'definition of behaviour in psychology pdf', directing users to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=definition+of+behaviour+in+psychology+pdf
    • http://juzufezike.mygamesonline.org/8537134811.pdf
    • http://bavimobuxadu.medianewsonline.com/85727892916.pdf
    • http://nuwojukow.mygamesonline.org/88657697059.pdf
    • http://sabovibin.medianewsonline.com/prayer_rain_by_daniel_olukoya.pdf
    • http://jobediniberine.scienceontheweb.net/11639494703.pdf
    • http://manovina.mypressonline.com/best_true_story_books_2020.pdf
    • http://donbetosstreettacos.com/vimizonomovoboraferhwfq.pdf
    • http://mekapidi.medianewsonline.com/top_10_machine_learning_algorithms_for_beginners.pdf
    • http://godezigupo.mywebcommunity.org/16955812643.pdf
    • http://devubowoku.mypressonline.com/patab.pdf
    • http://nasufulorejuwe.mywebcommunity.org/hp_pavilion_dv7t-7000_service_manual.pdf
    • http://zakewabo.scienceontheweb.net/kabaget.pdf
    • http://on-arenas.com/39404829817jo8tl.pdf
    • http://nopuvobetag.mygamesonline.org/cambridge_international_as_and_a_level_business.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://76c9fb28-c10e-4950-85be-37de24a2ede8.filesusr.com/ugd/fa32a6_bdfacb5d9b4c4697ae61fbaafeefbfcd.pdf?index=true
    • https://24451074-f53b-4065-993c-779ba3957988.filesusr.com/ugd/0ae25f_1b3c013f9cde43f5b4cc579581fffa29.pdf?index=true
    • https://cbb9655c-b60d-4095-8c1c-bb5f9a2903c5.filesusr.com/ugd/4dd980_a894ed4344db432cba5b1df6d1de4886.pdf?index=true
    • http://mobukug.myartsonline.com/turbochef_pizza_oven_recipes.pdf
    • https://b5b764bc-4fc6-48d7-9a4b-423a4d05f225.filesusr.com/ugd/3f2390_e486c4aaab474bf9be2378d00c5a3b3a.pdf?index=true
    • http://napamewa.atwebpages.com/sap_enterprise_asset_management_book.pdf
    • http://fuguzametekobo.myartsonline.com/faxeripezi.pdf
    • https://e114ad41-1367-46fe-a5fd-427bf640f69d.filesusr.com/ugd/a63c55_14ea6eef92364c1bb388e06b3e9c709e.pdf?index=true
    • http://safedoguno.onlinewebshop.net/jaxuragowafotalakiladulu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010614.bin
390993f8899a074ad27aa73b888b0762bb9f422ef6d926402544e1d73f11225d
pdf-font-stream PDF embedded font (sfnt) at offset 0x10614 5716 bytes
font_01_sfnt_off00011994.bin
8d9eb177378a006dc705f0bf3d417ebd4aaaa170ea8f13bfd708258f4b2a3f46
pdf-font-stream PDF embedded font (sfnt) at offset 0x11994 10632 bytes