Malicious PDF — malware analysis report

Static analysis result for SHA-256 4320b2c4e9400c9d…

MALICIOUS

PDF

99.9 KB Created: 2021-03-17 16:59:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bd777eded240779ab8c069ce7d874dc8 SHA-1: dcb6620ab5378889155aedc64ef648d26f271413 SHA-256: 4320b2c4e9400c9d7e863bd0b4079ff9030774627daa9d08ade4ff0664fa7685
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents. One of these links, https://jacksth.ru/wix?keyword=what+rhymes+with+guidance, is directly embedded in the document body. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or distributing further malware through the link farm.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9955

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=what+rhymes+with+guidance
    • https://cdn-cms.f-static.net/uploads/4365589/normal_601a9ba28edc0.pdf
    • https://static.s123-cdn-static.com/uploads/4469135/normal_600581a757725.pdf
    • https://cdn.sqhk.co/jirudumom/9icpibd/traffic_road_signs_and_meanings_in_uganda.pdf
    • https://cdn.sqhk.co/soxosovave/idmCggW/runescape_old_school_wiki.pdf
    • https://cdn.sqhk.co/guzufaseba/gf80jf7/5918727108.pdf
    • https://namulore.weebly.com/uploads/1/3/4/0/134017746/bemezunop-boxevesul-bujasaw-namol.pdf
    • https://cdn-cms.f-static.net/uploads/4384045/normal_604f8885cad20.pdf
    • https://cdn.sqhk.co/xupodafib/4ib1dCm/93263469715.pdf
    • https://cdn.sqhk.co/zezinojox/d6cii8W/one_gotta_go_game_food.pdf
    • https://cdn.sqhk.co/sigagegijej/Qjbhi7X/perfect_closing_gift_cutting_boards.pdf
    • https://bemofoserobonuw.weebly.com/uploads/1/3/0/7/130739893/9254605.pdf
    • https://merejeweja.weebly.com/uploads/1/3/1/3/131381112/latexerepugoworit.pdf
    • https://cdn.sqhk.co/ridasozewe/sJjdmgh/nba_2k20_myteam_draft.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.opentle.org
    • https://s3.amazonaws.com/galinikagopit/paul_ekman_emotions_revealed_francais.pdf
    • https://s3.amazonaws.com/vixuwogetiv/wedding_invite_template_wording.pdf
    • https://uploads.strikinglycdn.com/files/21816992-b4c6-41f3-a7d3-61ec207fb948/gewewulurafekato.pdf
    • https://s3.amazonaws.com/tarizirefevifab/catia_v5_license.pdf
    • https://uploads.strikinglycdn.com/files/0e578189-5337-4815-a55d-ee32290c83e0/short_story_length_for_publication.pdf
    • https://uploads.strikinglycdn.com/files/41f6ff3b-e5b0-449a-8101-3bc9f280482e/fire_and_ice_perfume_by_revlon.pdf
    • https://uploads.strikinglycdn.com/files/f80d889f-81ef-4b94-a467-dacc49e9d7d0/30123161786.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00015605.bin
36bf4bca2dbe62ed7eea770f09dcbd942e9f30cdfd175f8627c1a83adfc01dda
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x15605 18176 bytes
font_00_sfnt_off0000d2cb.bin
e0f0922da2f1b5a441c0ab47f148b203928c2bc4519f23812ab58bc0699b7f5d
pdf-font-stream PDF embedded font (sfnt) at offset 0xD2CB 5684 bytes
font_01_sfnt_off0000e6a7.bin
95eb097fd2ba2029cb97fdb19699b061573cbfedc41287f141c7796daa94a342
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6A7 5528 bytes
font_02_sfnt_off0000f961.bin
dbaab8dcf32bfe64cb008f34eb54f5316f62236e8dffe3de49b44225404383a5
pdf-font-stream PDF embedded font (sfnt) at offset 0xF961 2656 bytes
font_03_sfnt_off00010465.bin
c42118b51b061dffbc196cd4866a2cf76d9f31ae9d0a8f6c06e6ad224a677b24
pdf-font-stream PDF embedded font (sfnt) at offset 0x10465 2328 bytes
font_04_sfnt_off00010f1a.bin
806d12f4c18e044784d20764d58024893796e88f204c306662924b3e907cbcac
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F1A 2108 bytes
font_05_sfnt_off000118e5.bin
2da83060ad210a9a1743b04a22b2cc5ebb14ba7af64fbaa5f25da2d26a1b3d84
pdf-font-stream PDF embedded font (sfnt) at offset 0x118E5 6640 bytes
font_06_sfnt_off00012a83.bin
5246067f7ff5a16e05ea4eee7417c6ef111d11e93d1b94dfc7330676a2ea41c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A83 14376 bytes
font_08_sfnt_off000172d1.bin
c6f56f051084033b0538cdf61e3e457d22b7f2c2ea46d10ec59ebb2b81e63971
pdf-font-stream PDF embedded font (sfnt) at offset 0x172D1 3276 bytes