Malicious PDF — malware analysis report

Static analysis result for SHA-256 40b2297223032b5f…

MALICIOUS

PDF

123.0 KB Created: 2021-03-14 07:06:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9c9fd6dd8721e5ad352b5a4819c906ba SHA-1: 1be04f29ed4b267cab8d54558787ce81d6199458 SHA-256: 40b2297223032b5f53b638b64a513da9391c7ee76fb9e1548279b64eb403059f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to PDF files, indicating a link farm for SEO manipulation. One of the primary URLs, 'https://soxebez.ru/123?utm_term=android+studio+proxy+shadowsocks', suggests a potential lure related to software or proxy services. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/123?utm_term=android+studio+proxy+shadowsocks
    • https://vonepegoparopew.weebly.com/uploads/1/3/4/3/134352316/kuxel.pdf
    • https://navitadewota.weebly.com/uploads/1/3/4/0/134017874/99304f572.pdf
    • https://fefokepixax.weebly.com/uploads/1/3/1/4/131452923/9032715.pdf
    • http://grenkasalo4.xyz/725131013775h3hp.pdf
    • https://static.s123-cdn-static.com/uploads/4374517/normal_5fcb71ceb7343.pdf
    • http://flowerport.store/bosigamimugaloromde89b.pdf
    • http://meetcabinets.xyz/85563217558igbgw.pdf
    • http://usacreditmonitoring.info/653494131247nsgp.pdf
    • https://static.s123-cdn-static.com/uploads/4481552/normal_5fca58e8d076f.pdf
    • https://sodefabufu.weebly.com/uploads/1/3/4/4/134473286/bumewemotekagaf_zoxijijokipedag_xiwigelaka_vavoranujuvejog.pdf
    • https://cdn-cms.f-static.net/uploads/4444882/normal_6038905080252.pdf
    • https://revogofoti.weebly.com/uploads/1/3/3/9/133999152/0c20e10b3d.pdf
    • https://cdn-cms.f-static.net/uploads/4457011/normal_5fe9af997f319.pdf
    • http://trend-sales.fun/tajoxafazawujh884d.pdf
    • http://garderob-podolsk.ru/how_to_determine_polarity_of_a_power_supplysv32f.pdf
    • http://fenellalucynelle.info/cisco_networking_essentialsu727n.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://e4586023-485a-43f1-9451-2d404684c5b7.filesusr.com/ugd/95ff22_fa6c9380751b4665a2113d0bfe7205a0.pdf?index=true
    • https://7ef5d8b8-74ac-4e0a-b0a0-fa61ca6462a8.filesusr.com/ugd/23e9be_4dfafe3ec71043349c7ba46020ddf9fe.pdf?index=true
    • https://13ea8442-998f-4f14-ba3b-7f37e53a414c.filesusr.com/ugd/008a9f_429e04a49b584e668553c1f9ac1444c3.pdf?index=true
    • http://tokekiloxak.epizy.com/beginnings_and_beyond.pdf
    • https://1639490a-f715-481e-9fb1-af38d332269b.filesusr.com/ugd/a59130_c7190ff7801d446680ad3a33e64021b4.pdf?index=true
    • https://f3b86e06-b3aa-4ee1-82f7-79049f3379a8.filesusr.com/ugd/0c4fd2_3769784823c5444eb2e2dee34e47fb13.pdf?index=true
    • http://zonatenitisa.rf.gd/dhakad_chhora_full_hd_movie_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fc95.bin
710862cfc49368ec8d3644b976d8fea524a16ead528fe3f4d8973019e893d975
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC95 49920 bytes
font_01_sfnt_off00019437.bin
dcbb75b3cb06ad52b0e89cd9e01acc9240a57b24f1d600994122b0799e32a78b
pdf-font-stream PDF embedded font (sfnt) at offset 0x19437 5444 bytes
font_02_sfnt_off0001a6cf.bin
640d00d6d45d5d42ad1017f53bec17d6bde996d2bda8160c79c5c585560b3e62
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A6CF 16864 bytes