Malicious PDF — malware analysis report

Static analysis result for SHA-256 486c7127dba2bcc0…

MALICIOUS

PDF

78.0 KB Created: 2021-06-01 13:36:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 707a8e6b913bc856606e7afc3e0857f1 SHA-1: 78955e915d7a5aaecf81378cd02efd9c5b9ca3f9 SHA-256: 486c7127dba2bcc02432818541863499297f86ef0cb7c0126659d6d136cff3f5
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous external links, many pointing to link farms, suggesting an attempt to obscure the true destination of a download lure. The primary external URI, 'https://nomylo.ru/pbw?utm_term=pokemon+go+apk+mod+joystick+2020', is presented as a mod for Pokemon Go, a common social engineering tactic. While no scripts were explicitly extracted, the PDF structure and extensive link farm indicate a malicious workflow designed to trick users into downloading content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nomylo.ru/pbw?utm_term=pokemon+go+apk+mod+joystick+2020
    • https://zememaxuzibur.weebly.com/uploads/1/3/5/3/135326459/diwebi_xidinarikasij.pdf
    • https://lijupumo.weebly.com/uploads/1/3/4/4/134496400/3f988800768.pdf
    • https://dekavodo.weebly.com/uploads/1/3/4/4/134438155/vadogunabiva_rogezirutes_sagananagem.pdf
    • https://wezawelo.weebly.com/uploads/1/3/0/8/130813956/zudexutojujafub.pdf
    • https://wamukefak.weebly.com/uploads/1/3/5/3/135324497/48e95fa1961681.pdf
    • https://pimupaxepa.weebly.com/uploads/1/3/1/8/131857198/2eb2c1.pdf
    • https://lulipelewofepo.weebly.com/uploads/1/3/0/8/130873877/tumedubekow_kaxojinela_limudowig.pdf
    • https://vidokabotofasi.weebly.com/uploads/1/3/4/8/134868814/mexetaruzotozalajomu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://gatasulupu.pbworks.com/w/file/fetch/144412059/2019_hellcat_red_eye_charger.pdf
    • http://pugaxigodaka.pbworks.com/w/file/fetch/144443307/gufugu.pdf
    • http://siruzosu.pbworks.com/f/game_of_thrones_staffel_1_blu_ray_media_markt.pdf
    • http://xedidovetaw.pbworks.com/w/file/fetch/144425985/twas_the_night_before_christmas_old_book.pdf
    • http://jajafad.pbworks.com/w/file/fetch/144417279/idle_streamer_mod_apk_ios.pdf
    • http://negovijalulu.pbworks.com/f/kudi_mainu_kehndi_video_song_download_bestwap.pdf
    • http://barumena.pbworks.com/f/how_to_set_large_animal_trap.pdf
    • http://mutatalibo.pbworks.com/f/what_are_the_four_effects_of_baptism.pdf
    • http://jesababa.pbworks.com/f/11659084244.pdf
    • http://lakebimutep.pbworks.com/w/file/fetch/144418371/difference_between_direct_method_and_grammar_translation_method.pdf
    • http://pitevaj.pbworks.com/f/thinner_this_year_25_sacred_exercises.pdf
    • http://poforezufovu.pbworks.com/f/1585281092.pdf
    • http://tubekikewabi.pbworks.com/f/1773150487.pdf
    • http://volikedejefa.pbworks.com/f/67459397062.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ecbd.bin
00eab489b49302aa313d7f54b1ed8f375c9189c2408e33c27307d3e57d4540fc
pdf-font-stream PDF embedded font (sfnt) at offset 0xECBD 5784 bytes
font_01_sfnt_off0001007a.bin
09673e5f4a49b0f6fd1b8d9e557c761b5a335e654e0cea6a29f50e2bdd128c21
pdf-font-stream PDF embedded font (sfnt) at offset 0x1007A 13016 bytes