Malicious PDF — malware analysis report

Static analysis result for SHA-256 5bec7a3664bc3d04…

MALICIOUS

PDF

68.4 KB Created: 2021-04-06 14:09:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7e13648053ecb65f1b1d3de1ae215356 SHA-1: d92077b3f04233ff0b7a9e7f8e42d467cd20e882 SHA-256: 5bec7a3664bc3d04fa65a8d3418f2d0a67c37beb9916c95d654092577af64d1d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for a link farm and an embedded URI pointing to a URL that promises free gems for a game. This suggests a phishing or scam attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to redirect users to a malicious site or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=dragon+mania+legends+free+gems+no+survey
    • http://sobuvide.mygamesonline.org/pseudomonas_spp.pdf
    • http://jiwapadenejeza.getenjoyment.net/how_does_google_maps_traffic_data_work.pdf
    • http://godezigupo.mywebcommunity.org/todukofinogugekid.pdf
    • http://xomutukegadoj.mypressonline.com/samsung_aqua_jet_vrt_smart_care_washer_parts.pdf
    • http://sowoxapexemex.sportsontheweb.net/rodaxojunowop.pdf
    • http://ramuwesitavoz.mywebcommunity.org/48314734902.pdf
    • http://zobotalemogi.sportsontheweb.net/vajisukuvetosi.pdf
    • http://xitabijasava.getenjoyment.net/65423433406.pdf
    • http://jetinaxisodew.mypressonline.com/genetics_grade_12_notes.pdf
    • http://lixodamevurobar.mygamesonline.org/antigenic_shift_and_antigenic_drift.pdf
    • http://tevituvodejifep.mywebcommunity.org/48948280129.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/kobivimelelo/r_kelly_tp2.com_free_mp3_download.pdf
    • https://s3.amazonaws.com/jajoxulabojaso/geebung_weather_report_today.pdf
    • http://kakavogulogij.onlinewebshop.net/dabuxixogofe.pdf
    • https://s3.amazonaws.com/serogajugomiji/roriposilukesipaxibusom.pdf
    • https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_54b8efe1f00d46b89021ec21515194bb.pdf?index=true
    • https://6d8b2927-5c4d-40df-b593-c6bd35e19528.filesusr.com/ugd/1adac8_c202771cb3724ac5b906b34b14a0d46f.pdf?index=true
    • https://s3.amazonaws.com/pibajuwi/printable_baseball_box_score_sheet.pdf
    • https://9de673a2-3b8e-40eb-bbf5-c0ad8e71a3da.filesusr.com/ugd/bd5c68_4d7d00bd9b204103882aba56ff2d86fc.pdf?index=true
    • https://s3.amazonaws.com/zunaduxa/catequesis_semana_santa_para_nios.pdf
    • https://s3.amazonaws.com/davubewu/sotukovagoka.pdf
    • https://ed4d48c2-14ea-47f5-a89a-b82193587323.filesusr.com/ugd/8ce377_9872b344534b4ce88daea350e16540ae.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cda8.bin
9c8ffd55e7c96655c806441d68120bceebde6edd1fd477f791937cd89f015d66
pdf-font-stream PDF embedded font (sfnt) at offset 0xCDA8 5388 bytes
font_01_sfnt_off0000dffa.bin
ba2e673e4e2520b4863dbf790c2a653dd15963cc735a0c87c87808440aa4c451
pdf-font-stream PDF embedded font (sfnt) at offset 0xDFFA 10644 bytes