Malicious PDF — malware analysis report

Static analysis result for SHA-256 365c27a857e87d4d…

MALICIOUS

PDF

85.6 KB Created: 2021-03-18 11:22:57 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: afd3a13bd88c753aefd2ae46647da908 SHA-1: 9054b0ed57ddfcc1e018eced2ff67cf5489b26de SHA-256: 365c27a857e87d4d5ba0ff70f0db8ff58db71b14c3e58acfc867b68cc54a6146
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded external links, a technique often used for SEO spam or phishing campaigns. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=apkpure+call+of+duty+mobile
    • https://cdn.sqhk.co/ganinidunop/Ev8gdwp/94042647695.pdf
    • https://cdn.sqhk.co/lomekojop/hjNi7aT/54921089182.pdf
    • http://wosozage.mypressonline.com/how_to_multiply_and_simplify_square_roots.pdf
    • https://cdn.sqhk.co/sexuzoropa/dgdCjfV/dugadewapizofefagejalojel.pdf
    • https://cdn.sqhk.co/gepeduvo/INjbibt/75350644108.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/55e8f10b-10a4-4548-8cbe-fa1b2cceba0e/dyson_cordless_vacuum_cleaner_user_manual.pdf
    • https://uploads.strikinglycdn.com/files/a5e75c19-27fb-4a4f-b0c6-3b1c09084b19/vurimobomikufatuvu.pdf
    • https://uploads.strikinglycdn.com/files/fc9be29e-6079-4075-b4f2-374db8630432/15317174211.pdf
    • https://46d16763-6c5f-4e19-aa2c-3f4071fcbec2.filesusr.com/ugd/26f730_0d0bc15d6a544a73adf10ad5d26fe898.pdf?index=true
    • https://8fc1c2d6-49ba-4d63-8b95-0327ef2b1627.filesusr.com/ugd/1849a1_2e130efae4b04a6bb3ee844bba7e8655.pdf?index=true
    • https://8cff94d3-ecab-4ea5-ad27-d3e67d02fd32.filesusr.com/ugd/2813e2_df0503a7357a4bd19215040b743abf2b.pdf?index=true
    • https://s3.amazonaws.com/livivuvuwugeb/the_merchant_of_venice_summary_act_2_scene_4.pdf
    • http://rolubumemetujin.atwebpages.com/retulekixube.pdf
    • https://s3.amazonaws.com/ganubatebedoxez/kimenukobupedutenega.pdf
    • https://s3.amazonaws.com/tezofuretejom/africa_by_toto_trumpet_solo_sheet_music.pdf
    • https://uploads.strikinglycdn.com/files/0492a8ab-9fee-4984-b91e-fa6425b35c91/88792644496.pdf
    • https://b064d0e4-88d6-4b7e-8087-8ebf790fcba6.filesusr.com/ugd/ca32a8_d66de18ae92342279e5d9b4eefa9be75.pdf?index=true
    • http://nosigegu.onlinewebshop.net/tegizowegukinajowag.pdf
    • https://uploads.strikinglycdn.com/files/115d7ce1-12ee-4c8a-8e41-6a85c7a402a6/64414586441.pdf
    • https://5e54824a-8208-41b0-8aeb-7c017e8cfb46.filesusr.com/ugd/f64db8_d7bbec33be214e548e2b0705f478169b.pdf?index=true
    • http://xowobovu.myartsonline.com/how_to_turn_off_orbit_sprinkler_system.pdf
    • https://s3.amazonaws.com/muxegeza/bikekes.pdf
    • https://uploads.strikinglycdn.com/files/c634b1f1-d52d-44ac-adf7-da4b31a0154e/how_do_i_cook_a_turkey_in_a_rival_roaster_oven.pdf
    • https://s3.amazonaws.com/jevopemosod/reroru.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0001118b.bin
2e6c464205b114cd3b26718ecc77a59dc13795bc2839847b196382eaed439fe5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1118B 23536 bytes
font_00_sfnt_off0000d9a0.bin
84973ac198c3d2e3508cba1ba6bac13b9ac265a701e99acf8b2a962012aa4a21
pdf-font-stream PDF embedded font (sfnt) at offset 0xD9A0 5192 bytes
font_01_sfnt_off0000eb56.bin
9add2d3beb820e3d073b1105a5eb6da7ed00395d58ed6b3168962204f5f2a1e8
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB56 11168 bytes
font_03_sfnt_off00013a55.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x13A55 4324 bytes