Malicious PDF — malware analysis report

Static analysis result for SHA-256 45c736b58ea831ff…

MALICIOUS

PDF

78.6 KB Created: 2021-03-31 17:58:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: e04ddb453f9bf6580f6a6172f30d505f SHA-1: cb3a1385261eddcb0256ec6b9823268b044026bf SHA-256: 45c736b58ea831ffbc5ba01588c85e12f0b775495ae9bceeebc638e00dcbd9f6
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many pointing to disposable hosting, and one directly to a URL associated with malware distribution. The ML classifier and ClamAV both strongly indicate maliciousness, with ClamAV identifying it as a phishing trojan. The document body, though heavily obfuscated, contains references to 'cartoon hd apk 3.0.2', suggesting a lure to download potentially malicious software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=cartoon+hd+apk+3.0.2 PDF link annotation
    • https://cdn.sqhk.co/faserekino/gdidPf4/98918992598.pdfIn PDF document text
    • https://dapunilak.weebly.com/uploads/1/3/4/5/134506399/5765155.pdfIn PDF document text
    • https://cdn.sqhk.co/nupepewomaxu/iiv8Jij/crowder_all_my_hope_karaoke.pdfIn PDF document text
    • https://cdn.sqhk.co/todezuzutito/jajetpL/free_business_expense_budget_template.pdfIn PDF document text
    • https://cdn.sqhk.co/fogunivugame/gib6Kyz/36987014437.pdfIn PDF document text
    • https://likizosuzi.weebly.com/uploads/1/3/4/8/134886942/sevexa-pumumazapozam-jasabosegofav.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/1a97fa18-598f-434e-8222-a2c0fcc48902/clasificacin_de_cuentas_contables_activo_pasivo_perdida_y_ganancia.pdfIn PDF document text
    • https://16012499-1299-48b0-8cdd-5f23a7749958.filesusr.com/ugd/fafc38_71ad7fbf52484a54b74c9062572bc308.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/b89b8288-6a4d-45a1-b96e-bd5f37c3b278/what_are_the_specific_advantages_of_database_management_system_over_traditional_file_processing.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4cd1bba9-2d87-4462-ae64-5d3a1530c31e/evh_5150_iii_lbx.pdfIn PDF document text
    • https://b564fea6-732e-489f-a029-a72dc6590de2.filesusr.com/ugd/6a4619_cb74a7cacb0c4bec9b74437796a95350.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/8e66ff57-663d-4dd1-ad49-41567f53fd40/how_far_is_voyager_1_2019.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0f7b5c36-7fd4-45b0-84ed-f9c33478c531/what_does_error_code_f20_mean_on_a_whirlpool_duet_washer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/793ff4a8-8095-4367-8238-80e891bca76e/84772493624.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2f535b19-e58a-40d5-a6fa-8d771cab8c81/tipos_de_sistemas_de_informacin_administrativa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e99ebdea-cbda-4de4-a263-143767a3d84c/honeywell_hyf290e_quietset_tower_fan_review.pdfIn PDF document text
    • https://eda93683-a6ca-45e9-8056-ca7adea7f1dc.filesusr.com/ugd/d655db_e99dfa8a174345bc917a2d5d2d112869.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/6d06bad0-ce42-4e90-950c-c0a0cbeeb1dc/persuasive_essay_writing_graphic_organizer.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d74554e8-b780-43fd-bd1e-d36b93f2401a/64138681136.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8b81c835-0632-435a-ac6b-f6fa4c925198/mumub.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/baa5c9ed-832e-40e4-a93b-3aa4e2e56d57/janimedakodikaxo.pdfIn PDF document text
    • https://ea64ff4c-51e6-4efc-8cc1-399682447901.filesusr.com/ugd/961f18_795c091291474c21802baec787069b16.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/baa92520-81aa-4325-88f8-47f38324ad39/30657361907.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/af02328b-5154-4a44-a50e-407299084279/systems_engineering_group_salary.pdfIn PDF document text
    • https://c3373aeb-ed74-4f2d-b631-fa679e0a3f6f.filesusr.com/ugd/cbe7f7_44bbdbf003574414bdf0802a95a4e45f.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3a8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF3A8 5276 bytes
SHA-256: 03bfc425e09dd53ad0d5ba51c00d8178172e52cfe8375ffc61a7d1c117875ba6
font_01_sfnt_off00010596.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10596 11612 bytes
SHA-256: def02006ad548f27de3e687190c46a59412ba56d8ed76d926e8affb5d15cfeae