Malicious PDF — malware analysis report

Static analysis result for SHA-256 6490bc1902434587…

MALICIOUS

PDF

116.0 KB Created: 2021-03-09 15:44:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-06-17
MD5: 388ecacb53b3a574d3906c78a60ce115 SHA-1: 00addfbf81ee751cd6406eb265a4b6584aee7e98 SHA-256: 6490bc1902434587811924644f574b39ea1f5abd233ac4f4a721b4c43d04471d
216 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-themed, suggesting a link farm or redirection scheme. The heuristic 'SE_SECRET_RECOVERY_LURE' indicates the document may also attempt to trick users into revealing sensitive information. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9947

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=what+is+an+object+oriented+program PDF link annotation
    • http://kopogaxepaku.sportsontheweb.net/matlab_plot_line_size.pdfIn PDF document text
    • https://gamuzajebi.weebly.com/uploads/1/3/4/4/134481120/rumiwizalan.pdfIn PDF document text
    • http://vevufilusik.scienceontheweb.net/68221104990.pdfIn PDF document text
    • http://newyearshop.site/16518470500gaeri.pdfIn PDF document text
    • http://topstop.site/71313884998wg5my.pdfIn PDF document text
    • http://pasetbs.xyz/new_moon_graphic_novel_volume_1_read_online_free43bjt.pdfIn PDF document text
    • http://kixiwogazu.sportsontheweb.net/beats_studio_wireless_3_price_philippines.pdfIn PDF document text
    • http://fherixq.com/487683191720c7kn.pdfIn PDF document text
    • http://ribavid.medianewsonline.com/tujopelileb.pdfIn PDF document text
    • http://fijazubelanulek.mywebcommunity.org/clinical_data_interpretation_in_anaesthesia_and_intensive_care.pdfIn PDF document text
    • https://kowenijog.weebly.com/uploads/1/3/4/0/134096242/pokam.pdfIn PDF document text
    • http://yesstore.pro/le_gone_du_chaaba_livre_en_ligne4na1o.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/tawovojo/jawogejamabe.pdfIn PDF document text
    • http://rixuroruwe.myartsonline.com/venstar_t2700_eh.pdfIn PDF document text
    • https://s3.amazonaws.com/fezenur/language_leader_elementary_answer_key.pdfIn PDF document text
    • https://s3.amazonaws.com/vapite/5061362406.pdfIn PDF document text
    • https://s3.amazonaws.com/womirofop/latest_bollywood_song_whatsapp_status.pdfIn PDF document text
    • https://s3.amazonaws.com/woxorojero/samsung_galaxy_note_20_ultra_specs_and_price_philippines.pdfIn PDF document text
    • https://s3.amazonaws.com/fogibi/6572770827.pdfIn PDF document text
    • https://s3.amazonaws.com/gulapore/fedoje.pdfIn PDF document text
    • http://vamavaremimot.atwebpages.com/plan_de_negocio_para_abrir_una_cafeteria.pdfIn PDF document text
    • https://s3.amazonaws.com/gulapore/ronujabipot.pdfIn PDF document text
    • http://vilepobafomunow.atwebpages.com/what_was_the_renaissance_in_western_europe_noted_for.pdfIn PDF document text
    • http://nukilaba.myartsonline.com/53335883091.pdfIn PDF document text
    • http://lufevexos.atwebpages.com/transverse_abdominis_exercises_physical_therapy.pdfIn PDF document text
    • https://s3.amazonaws.com/pesetufavo/wapking._com_latest_song.pdfIn PDF document text
    • https://s3.amazonaws.com/resabomibogodaw/easy_cubism_art_templates.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018759.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x18759 5684 bytes
SHA-256: 1da60cd6c09c219ac3550172adc0e7a25a421b38ad272f0f16c84f32f01150ed
font_01_sfnt_off00019a90.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19A90 11836 bytes
SHA-256: 0e4fa30416f2b63114d91e590068bae00e011c39c1f98e1f863d9a7f2a31b6da