Malicious PDF — malware analysis report

Static analysis result for SHA-256 5297e19262dd3433…

MALICIOUS

PDF

83.6 KB Created: 2021-04-08 22:53:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d9dd9bff9f864dee904d1aacbeb9a51d SHA-1: 953b8a68e4d9e0281c6628dd958af33b0f100655 SHA-256: 5297e19262dd3433a7108dd3b3add9504bbf6e8c9158b505322e6d4653917595
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are disguised as PDF documents, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent, specifically phishing. While no scripts were explicitly extracted, the presence of numerous external URIs and the PDF_SEO_LINK_FARM heuristic point towards an attack pattern designed to redirect users to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/strik?utm_term=husqvarna+323r+ii+manual
    • http://junumidutuzakox.getenjoyment.net/analogies_for_critical_thinking.pdf
    • https://cdn.sqhk.co/libobivole/jhMgjge/ice_hockey_skates_ccm.pdf
    • https://cdn.sqhk.co/tovasodoj/iKhjbhf/ziwikak.pdf
    • https://cdn.sqhk.co/xexisini/4giijJW/bandwagon_advertising_techniques_examples.pdf
    • http://viwivomoxori.22web.org/19791392564.pdf
    • https://cdn.sqhk.co/keximovib/qFifjaO/13582255624.pdf
    • https://cdn.sqhk.co/woxekivepi/hbgcqic/30_day_fitness_challenge_workout_at_home.pdf
    • http://xijipeva.mypressonline.com/accident_proneness_theory.pdf
    • http://excschool.ru/rivixefuziparxgoyn.pdf
    • http://apple-fruit.space/39010032467ra7e6.pdf
    • http://brosbass.com/4371476308isr3b.pdf
    • http://puwufonizezez.22web.org/afaan_oromoo.pdf
    • http://bukipumil.mypressonline.com/business_application_software_2.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://sawesupunozigiv.atwebpages.com/79309238881.pdf
    • https://28546a20-d0cc-4b82-bb4f-6711990cd5a3.filesusr.com/ugd/0bcf16_c1760abf680e4c42ac261c68f95526a5.pdf?index=true
    • http://mutodilevo.epizy.com/benkelman_beam_test.pdf
    • http://sumolusekoximu.rf.gd/vox_ac15c1x_vs_ac15hw1x.pdf
    • http://fojosotum.myartsonline.com/nelejomumaroxilo.pdf
    • http://zutaturusix.myartsonline.com/34327720974.pdf
    • https://be56f97b-0727-4a8e-a141-4155b83e75ac.filesusr.com/ugd/5034d0_a09a7299c699478f8e8b62da7a46f11f.pdf?index=true
    • http://muliwavanebebo.onlinewebshop.net/vukomazirexexerojavotenam.pdf
    • http://filipebed.rf.gd/sultans_of_swing_alchemy_tab.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e46b.bin
73942ac41426111e4d572c4e3e6ed4746b7608924e63c8e0502727b694a11418
pdf-font-stream PDF embedded font (sfnt) at offset 0xE46B 5272 bytes
font_01_sfnt_off0000f648.bin
3ca9e6282d0b3a1817afa7fb16429aa76ae51a7d8763e743d9b93ad92aa3c688
pdf-font-stream PDF embedded font (sfnt) at offset 0xF648 11060 bytes
font_02_sfnt_off00011c4b.bin
9853a4a918762215dfcba51349555ff48d39e56332efe18e2f333ca30d8a5b61
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C4B 16096 bytes
font_03_sfnt_off00013151.bin
92361f73a2ec4782dba32e0e9e9cfeae7e6a867272159ca21ce3564319609964
pdf-font-stream PDF embedded font (sfnt) at offset 0x13151 4012 bytes