Malicious PDF — malware analysis report

Static analysis result for SHA-256 4216a904a1fe0632…

MALICIOUS

PDF

81.7 KB Created: 2021-06-01 10:47:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 76f1046e50e42ca5483a868cfed46418 SHA-1: d142ed8539653e996ed36f31f64a75fa6ed83c06 SHA-256: 4216a904a1fe06322862578a7da1ce5a04dc0979841e6583153462900e06dcd9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with one heuristic specifically identifying a 'PDF link farm' designed for SEO manipulation. The embedded content, though heavily obfuscated, suggests a lure related to 'Jules jurgensen watch identification' pointing to a suspicious URL. ClamAV detection and ML classification strongly indicate malicious intent, likely phishing or a scam.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://garglob.ru/pbw?utm_term=jules+jurgensen+watch+identification
    • https://cdn-cms.f-static.net/uploads/4421615/normal_60381830c3d31.pdf
    • https://cdn-cms.f-static.net/uploads/4390643/normal_60137032a08ff.pdf
    • https://xeganixirutor.weebly.com/uploads/1/3/4/5/134508666/xedisosatubotop.pdf
    • https://cdn-cms.f-static.net/uploads/4468550/normal_605bfe5f94129.pdf
    • https://static.s123-cdn-static.com/uploads/4411702/normal_5ffad4a031b7b.pdf
    • https://cdn-cms.f-static.net/uploads/4402481/normal_603d4791bc7b6.pdf
    • https://xofujudafovebe.weebly.com/uploads/1/3/1/4/131410434/wadudeniwiliboludof.pdf
    • https://cdn-cms.f-static.net/uploads/4367622/normal_5fdbbf5971ecc.pdf
    • https://rixidagetowema.weebly.com/uploads/1/3/4/6/134612143/36191c9.pdf
    • https://sadaxolofomet.weebly.com/uploads/1/3/1/4/131453623/6648964.pdf
    • https://cdn-cms.f-static.net/uploads/4446259/normal_601f940c8a6e4.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/cd82e94d-e277-4d12-b8a2-4fba0438d94d/ropirolalujo.pdf
    • https://uploads.strikinglycdn.com/files/c039451a-5b50-4847-9773-a5ba0a5e50af/service_engine_soon_light_blinking_nissan_altima.pdf
    • http://negovijalulu.pbworks.com/f/rijisixowojatenorejime.pdf
    • https://uploads.strikinglycdn.com/files/e320d929-80da-48c0-b31d-1b722fca572c/rijiwufapimun.pdf
    • http://ziduzobif.pbworks.com/f/galugefido.pdf
    • https://uploads.strikinglycdn.com/files/3d70c135-5ecb-43fd-8249-55e50265824c/how_to_know_gucci_belt_size.pdf
    • https://uploads.strikinglycdn.com/files/bf20e87b-6612-4aa0-b40b-94605f61efbc/54755798326.pdf
    • https://uploads.strikinglycdn.com/files/7e0abe78-0644-4974-9e3d-62c3148fb9aa/new_testament_baptist_church_butler_pa.pdf
    • https://uploads.strikinglycdn.com/files/00a7262f-a799-45cc-b6c7-989b54db9124/main_sources_of_carbon_dioxide_in_the_air.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0ff.bin
8e058fb27c41639c0a9ccb14a6cdf722a9801e33cb2f70ac0609a9894770d8c3
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0FF 5324 bytes
font_01_sfnt_off0001031a.bin
7928fd7a9da909f5ca3eeaa0a414cf5d64cc56b347b1a52329d5db5555b5deb7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1031A 11988 bytes
font_02_sfnt_off00012b8c.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x12B8C 4324 bytes