Malicious PDF — malware analysis report

Static analysis result for SHA-256 407c85a4ff389b44…

MALICIOUS

PDF

79.3 KB Created: 2021-03-16 11:18:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eacc08f5710b216fa0ce22ad3aad579a SHA-1: 5916f14a4551c097f735fe41c9f20e13995b2a93 SHA-256: 407c85a4ff389b44aaa51315084d0a9228281970d6edefd47c06b02a2d127084
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which appear to be part of a link farm designed to artificially inflate search engine rankings. The document body, though heavily obfuscated, contains keywords related to cancer treatment, suggesting a lure. The presence of ClamAV detection and ML classification strongly indicates malicious intent, likely for phishing or malware distribution via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=tratamento+do+cancer+de+colo+de+utero+pdf
    • http://komaxinatobofe.medianewsonline.com/dell_optiplex_9020_micro_i7_specs.pdf
    • https://cdn.sqhk.co/zidexamuwela/rjihiji/e_pluribus_unum_penny_2014.pdf
    • http://lemakomude.sportsontheweb.net/95591065897.pdf
    • https://cdn.sqhk.co/xupodafib/gho7iLV/mojo_story_maker_for_instagram.pdf
    • http://doguvejefejit.22web.org/my_samsung_gas_oven_wont_heat_up.pdf
    • http://fudoviwil.mywebcommunity.org/proper_care_and_feeding_of_marriage_summary.pdf
    • https://cdn.sqhk.co/wumidimux/ihg9hgY/likes_on_facebook_post.pdf
    • https://cdn.sqhk.co/rifelefiw/47ItPha/vavafedosod.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://6632aaff-1fe9-4f1d-acb3-7d444e457837.filesusr.com/ugd/ce4b7c_05799c753b444df98e8f08293ea63e84.pdf?index=true
    • https://5a11eff3-0c7a-45dd-bb89-060d4d4d2060.filesusr.com/ugd/72216b_75d8a2c3c77844d9840a9f1dc5a94e66.pdf?index=true
    • http://desasivitusuzux.epizy.com/toshiba_dvd_recorder_dr410_manual.pdf
    • https://27158da8-170d-48ca-a528-b8ced62fe517.filesusr.com/ugd/9fc8c3_f3728e93d0cf4bb794935a2b1663d18c.pdf?index=true
    • http://logoroxesum.epizy.com/video_editing_android_full_apk.pdf
    • https://2ed821ec-8078-4e74-b11b-c5cec6a88262.filesusr.com/ugd/65e777_b08fd02b8b1e4e3fb33c6e2e6554a5dd.pdf?index=true
    • http://kimoviranonaf.onlinewebshop.net/15950349858.pdf
    • https://64e18f06-8a0e-4dc1-8427-9dd81b4bff36.filesusr.com/ugd/baa514_87cdd5ac811f4ace855dc9f817e3ee4f.pdf?index=true
    • https://17c3d818-7f64-4152-976a-2fa997d7a7be.filesusr.com/ugd/e2c250_2d5e891876be47fbb58445dbc1386e9b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f6b3.bin
34884dfee965d0a178c6c30dd23fae1ba64bef770a8c15819c4d26c15a9a14a9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6B3 5072 bytes
font_01_sfnt_off000107dd.bin
49c66e92fbd7157789fa285dcdb13d46031ba80a99d67ed88c6774636306774d
pdf-font-stream PDF embedded font (sfnt) at offset 0x107DD 12700 bytes