Malicious PDF — malware analysis report

Static analysis result for SHA-256 51dc31429228b87b…

MALICIOUS

PDF

89.6 KB Created: 2021-04-21 09:49:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: ace5a0015740b1f783ea8b1c5f8390fe SHA-1: 89e9fbd9c006315e03dc6c314ceadfe807cc84cd SHA-256: 51dc31429228b87bfba5a1feff91196c180a8b52d3ce15ee514ad0a5abd958bb
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying it as a 'PDF_SEO_LINK_FARM'. One of the primary external URIs points to 'lozipotod.ru', a domain commonly associated with malicious activity. ClamAV also detected this file as 'Pdf.Phishing.Trojan'. The presence of embedded links and the overall structure suggest an attempt to direct users to malicious content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/strik?utm_term=is+snow+flower+and+the+secret+fan+a+true+story PDF link annotation
    • http://modebedunizux.iblogger.org/kilinujafu.pdfIn PDF document text
    • https://cdn.sqhk.co/rokajoten/gejeie0/liboralapaxipuvesapazitel.pdfIn PDF document text
    • https://cdn.sqhk.co/gixelotopa/Dgc9FOU/bubowepawu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/defujo/26754327229.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a08c989f-b91a-48fd-be7e-eb84cbf1ba03/how_do_you_reset_a_bowflex_treadmill.pdfIn PDF document text
    • https://s3.amazonaws.com/timeziso/jesus_calling_daily_reading_for_today.pdfIn PDF document text
    • https://s3.amazonaws.com/polojuliragam/the_odyssey_fagles.pdfIn PDF document text
    • http://fefekakase.epizy.com/audi_a3_2015_manual_transmission.pdfIn PDF document text
    • http://bilitejevi.rf.gd/amazing_grace_organ_sheet_music.pdfIn PDF document text
    • https://49f3a523-2ddb-4f17-a073-729d67a362fa.filesusr.com/ugd/18c683_e4ba39e7d5c74f92afae2b2d74c46541.pdf?index=trueIn PDF document text
    • https://e6e31949-ba74-43ae-8e0c-2243355e89fd.filesusr.com/ugd/69e259_9d696484d1a84bf7a5faeaaabed0bf86.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/34ba0841-0e53-4a0d-9317-514bb565908a/kowirinap.pdfIn PDF document text
    • https://91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com/ugd/dad90e_f6f916d5850f4069bd453b237026b6fd.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/72f92aa0-bfcf-4e1e-8e66-65663cfa2bee/are_old_readers_digest_books_worth_any_money.pdfIn PDF document text
    • https://9f4ad419-87ad-4507-9b23-40b7c7395cc9.filesusr.com/ugd/55478e_76363071de1545f4a8cb882859cea6be.pdf?index=trueIn PDF document text
    • https://27f1a270-5048-4778-87f0-574dfe85248a.filesusr.com/ugd/b7306e_fc22afceddc14ddcb73d0ec570125673.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/wamatasamegu/tonakonutezodazoxadu.pdfIn PDF document text
    • https://39ad70c8-6a03-4de2-a89b-b0209cba5754.filesusr.com/ugd/d2759c_29b75dda19b8492ba17a44311c62905a.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1cafcc4-718b-4329-afdc-9f2b0ca7c41a/59418858837.pdfIn PDF document text
    • https://c6de0af5-2a4c-46da-924c-839bccb102c6.filesusr.com/ugd/5f1f0f_78cae537f96d42d7bcec0379ea695107.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/dopugaxelelema/balancing_chemical_equations_worksheet_class_10.pdfIn PDF document text
    • https://c7bff75e-0a19-4817-9d47-fca4cf08161b.filesusr.com/ugd/3b6424_6e1f19cac446414a8c85eeb6519e6665.pdf?index=trueIn PDF document text
    • http://vipowiso.epizy.com/vector_addition_using_components_worksheet_answers.pdfIn PDF document text
    • http://dikazimizoban.epizy.com/curso_de_apologetica_catolica.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012016.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12016 5240 bytes
SHA-256: 8062522bbec2268954587e60cbf6f00c86a0ae9ab5e7d4718dec0d77a54ff4d4
font_01_sfnt_off000131f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x131F8 10860 bytes
SHA-256: eb6ae9a2ee13a71b67afdebc29ed4a18027679dd9cfee7e7451e6210cfdb97fe