Malicious PDF — malware analysis report

Static analysis result for SHA-256 50e9f2462c379954…

MALICIOUS

PDF

95.7 KB Created: 2021-05-28 18:52:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 65528755f27d2b8729e804b549ac0370 SHA-1: 6aa16db030c0c4240f964ab0134777e15a0525d7 SHA-256: 50e9f2462c379954b2c21242c7a91d6c742df87ca6739d346ce0e4c72cfd65c4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to other PDF files hosted on various domains, suggesting a link farm or phishing operation. The document body, though heavily obfuscated, contains text related to search terms, further supporting the lure. ClamAV and ML classifiers also flagged this PDF as malicious, specifically as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/123?utm_term=anjali+anjali+pushpanjali+telugu+songs+free
    • https://cdn-cms.f-static.net/uploads/4367268/normal_6066ab9c09ea1.pdf
    • https://xovodozavaso.weebly.com/uploads/1/3/1/0/131069890/watewebufesi.pdf
    • https://jojobejuw.weebly.com/uploads/1/3/2/8/132815094/ed09086.pdf
    • https://fevixivosetakub.weebly.com/uploads/1/3/2/6/132681861/6748833.pdf
    • https://zubosevofugojat.weebly.com/uploads/1/3/4/3/134307347/5815c24695.pdf
    • https://veretiwuwe.weebly.com/uploads/1/3/1/4/131406621/4952467.pdf
    • https://betiriwusogaz.weebly.com/uploads/1/3/1/3/131380032/bbc27453.pdf
    • https://gibuximo.weebly.com/uploads/1/3/4/6/134665594/fekelanejisafosuz.pdf
    • https://warororob.weebly.com/uploads/1/3/5/3/135314520/6e3bdda.pdf
    • https://bugituwixumanuz.weebly.com/uploads/1/3/4/7/134722584/ridukufubalaz-dapaxad-sanod.pdf
    • https://fopilifufisi.weebly.com/uploads/1/3/6/0/136055159/fesebakifugu_dobotepafoxegu_dopilewenukif_liwutumowemi.pdf
    • https://midinomuxew.weebly.com/uploads/1/3/5/3/135391973/e3fc23ba.pdf
    • https://boxatikavizag.weebly.com/uploads/1/3/4/6/134680825/xonopibi-zejarupikeved-tanupojeluwunoz-bobupupukuroba.pdf
    • https://static.s123-cdn-static.com/uploads/4388613/normal_5fcd5126e6368.pdf
    • https://waluxine.weebly.com/uploads/1/3/4/7/134759732/55ec783788d70.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://uploads.strikinglycdn.com/files/b20ea2ed-7a17-43b3-8225-81567dd08205/98895787025.pdf
    • https://uploads.strikinglycdn.com/files/7838c585-f015-49c8-9f84-e5091f6f983d/how_to_change_code_liftmaster_garage_door_opener.pdf
    • https://uploads.strikinglycdn.com/files/f6ee2b88-fb23-4177-b14c-1599b0429696/south_african_theatre_history.pdf
    • https://uploads.strikinglycdn.com/files/0a91ae9d-73ba-4ada-90f1-4b6620837a38/how_do_i_install_a_previewer_in_outlook_2010.pdf
    • https://uploads.strikinglycdn.com/files/9b3f8a72-ea96-43c9-abae-46296b8eaf27/jutebip.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fee1.bin
0727b87ad5548ea575670a30420b16b46036624717029944d86f165a640bc4af
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEE1 5228 bytes
font_01_sfnt_off000110a5.bin
82f3a051cf03dbfad69a17406ccf50c3f9ba01cb0394eaf646058fa3606e7394
pdf-font-stream PDF embedded font (sfnt) at offset 0x110A5 4976 bytes
font_02_sfnt_off000121f1.bin
499ed5d5faa133fc07a3a4a1a0a7c139667084dd2ff543bfefb75ee743829513
pdf-font-stream PDF embedded font (sfnt) at offset 0x121F1 11492 bytes
font_03_sfnt_off00014937.bin
c988415812f594187b0a0ed75dc52802e798e1695b49bd300f8412a65040a449
pdf-font-stream PDF embedded font (sfnt) at offset 0x14937 16204 bytes
font_04_sfnt_off00015ea2.bin
1b0af08576bc623ff3613805e6644d0d76a69dedf89093faf686c6674ee4f4f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x15EA2 4772 bytes