Malicious PDF — malware analysis report

Static analysis result for SHA-256 619578b59edb7fef…

MALICIOUS

PDF

94.8 KB Created: 2021-03-21 03:21:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 61242bb177a2c0c514ca5172d6df2b1c SHA-1: 2453970585a2aa58090fd2737735f91d856469b6 SHA-256: 619578b59edb7fef4d3dea1c1830f744e72d62a93d909c872cf2ced72e0dd652
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with one heuristic specifically identifying a 'PDF_SEO_LINK_FARM' pointing to multiple PDF files. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. The embedded URLs suggest an attempt to redirect the user to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9984

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=mbox+pro+3+manual+espa%25C3%25B1ol
    • https://cdn-cms.f-static.net/uploads/4419195/normal_5fdbc281d3b8e.pdf
    • https://rovenefewapug.weebly.com/uploads/1/3/0/7/130775308/83c345b896c.pdf
    • https://kidodizaramaba.weebly.com/uploads/1/3/4/0/134096495/xefudubofaninija.pdf
    • https://cdn-cms.f-static.net/uploads/4444115/normal_6027890bf41a1.pdf
    • https://cdn-cms.f-static.net/uploads/4384459/normal_605428c28c791.pdf
    • https://fumuzuwuwuwupu.weebly.com/uploads/1/3/0/9/130969925/jovipifenul_judaregen_felepumewowud.pdf
    • https://cdn.sqhk.co/ratijojitud/R6onX7Z/space_crew_review_ps4.pdf
    • https://cdn-cms.f-static.net/uploads/4413696/normal_6030eb4b39b2a.pdf
    • https://tadilagene.weebly.com/uploads/1/3/1/3/131381422/xuxusekovewo-jozabax-xamukuz.pdf
    • https://cdn-cms.f-static.net/uploads/4469834/normal_60430be04feae.pdf
    • https://cdn-cms.f-static.net/uploads/4496204/normal_60558f8fba38d.pdf
    • https://cdn-cms.f-static.net/uploads/4486969/normal_600adc8629696.pdf
    • https://cdn-cms.f-static.net/uploads/4485587/normal_602fcf9d9ce0c.pdf
    • https://cdn.sqhk.co/sezivalaw/2gcegcM/2_player_soccer_drills.pdf
    • https://static.s123-cdn-static.com/uploads/4470982/normal_5ff65ce029b65.pdf
    • http://fontawesome.iohttp://fontawesome.io/license/
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://borogibapomad.epizy.com/76929488409.pdf
    • https://uploads.strikinglycdn.com/files/0152f12e-736f-40c3-bfd9-fb6fe03d4c25/how_to_do_a_diagnostic_test_on_a_whirlpool_dishwasher.pdf
    • https://uploads.strikinglycdn.com/files/fb77e0e3-6b54-4b97-ada3-eb792a39f45f/vimazuvuw.pdf
    • https://uploads.strikinglycdn.com/files/30e64269-f49a-4564-a73e-1c874c5fb189/95401052666.pdf
    • http://waminakukivexo.rf.gd/zotonekigomoma.pdf
    • https://uploads.strikinglycdn.com/files/24000d76-d700-4614-90a5-ca42198f0285/al_quran_price_in_bangladesh.pdf
    • https://uploads.strikinglycdn.com/files/812c0b8b-6b07-4353-92f8-d64be639d400/3406021449.pdf
    • http://wemiwapava.epizy.com/crinkleroot_s_guide_to_animal_habitats.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000108f8.bin
9c30ad3c9974021b1baea6b7942ec5241a57ee8ea3de3c6cf143c689e3240c23
pdf-font-stream PDF embedded font (sfnt) at offset 0x108F8 8988 bytes
font_01_sfnt_off0001270b.bin
90fb1042126c15d8a796f6f88dc26108755fb6ca519e05b6d0de05ca6d3d969f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1270B 1724 bytes
font_02_sfnt_off00012f95.bin
7af67783303a7ae9874590e2b859e6eab9f1a1f99fdda4ae781ae39c65e03ef3
pdf-font-stream PDF embedded font (sfnt) at offset 0x12F95 5556 bytes
font_03_sfnt_off00014227.bin
2c38a862b4196a09392384f83cdc5d41e9ddbfad823fcb7bce46850cbfdcd14c
pdf-font-stream PDF embedded font (sfnt) at offset 0x14227 13492 bytes