Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e9b679c4b630a66…

MALICIOUS

PDF

80.6 KB Created: 2021-03-17 08:06:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4fd3aa1cdbb6421fb92d834c1b37040 SHA-1: 47d3133dcc3b11f9bab6c286362f0476e76f350e SHA-256: 4e9b679c4b630a66f29bbc0702992c158ffdbc2a5ea428633b80c4fa7e060cc5
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to S3 buckets and other domains, indicative of a link farm or SEO manipulation scheme. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. No scripts were extracted, but the PDF structure and numerous URLs point towards an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=time+is+the+longest+distance+between+two+places
    • http://bumawusuka.mypressonline.com/ielts_essay_writing_download.pdf
    • http://boketizabujig.scienceontheweb.net/cctv_camera_types_and_specifications.pdf
    • https://rotafejejulivis.weebly.com/uploads/1/3/4/5/134599198/dusawane.pdf
    • http://dapujabowigu.sportsontheweb.net/tazigikabonaxa.pdf
    • https://cdn.sqhk.co/takabalal/cBihyMQ/crecimiento_microbiano_definicion.pdf
    • https://cdn.sqhk.co/gufezitaxato/iiggDmN/island_tribe_3_walkthrough.pdf
    • https://cdn-cms.f-static.net/uploads/4388815/normal_6045f8b5b0211.pdf
    • https://cdn.sqhk.co/wiluxuko/ihbhhjb/ghost_picture_prank_app.pdf
    • https://cdn-cms.f-static.net/uploads/4453118/normal_5fd7ea677a280.pdf
    • https://cdn.sqhk.co/sisalubitot/hSNMjcT/7357944525.pdf
    • https://static.s123-cdn-static.com/uploads/4468289/normal_5ff21c8f6de9d.pdf
    • https://cdn.sqhk.co/firimubujosu/RTC8qMH/real_steel_game_online_unblocked.pdf
    • https://cdn.sqhk.co/baxajufim/jai1hat/best_slasher_build_2k20_that_can_shoot.pdf
    • https://cdn.sqhk.co/noviraxat/tNgFgeg/zombieland_afk_survival_rule_21.pdf
    • https://cdn.sqhk.co/wumerelup/egfVwjd/85693725239.pdf
    • https://static.s123-cdn-static.com/uploads/4501231/normal_60078a63da5e7.pdf
    • https://static.s123-cdn-static.com/uploads/4476569/normal_5fc833a72f56b.pdf
    • https://lasuzolus.weebly.com/uploads/1/3/5/3/135315371/xoniwinitirodalo.pdf
    • https://cdn.sqhk.co/xovujiroveg/a4jgKJS/guess_the_hollywood_celebrity_and_earnest_money.pdf
    • http://vitofemegawe.getenjoyment.net/is_lean_six_sigma_white_belt_worth_it.pdf
    • https://awan.com.npOutbreaks
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/fuwuzerijofa/22926771938.pdf
    • https://s3.amazonaws.com/zuxime/gifimurizigovurasuzejami.pdf
    • https://s3.amazonaws.com/tixedujegibex/borneras_electricas.pdf
    • https://s3.amazonaws.com/bejenosugede/order_of_marvel_movies_to_watch_before_avengers_endgame.pdf
    • http://pogetowem.onlinewebshop.net/37388878992.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb5e.bin
8642a3d72899a80ee4c7ebcdcd92cf2382b98b5b9cad4bc6ed1fb0d1b4573f3f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB5E 5572 bytes
font_01_sfnt_off00010e3b.bin
4f28d765175cb614fe1d171a3df1c394081a7187727af3083e0c40c77bf844fd
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E3B 11232 bytes