Malicious PDF — malware analysis report

Static analysis result for SHA-256 670706a1d08a4ac4…

MALICIOUS

PDF

80.1 KB Created: 2021-03-13 14:16:48 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0696a2b67b7a26239d74778da9df05d4 SHA-1: 789e8dfef8503f7842517069a4bc407781f9d6a4 SHA-256: 670706a1d08a4ac49229ea352169eadf9e092768d37eefcb90248185f07f99ba
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a technique often used for SEO poisoning or phishing. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as a phishing trojan. The embedded URLs, such as 'https://jacksth.ru/award?keyword=deficiencia+de+vitamina+b12+tratamiento+pdf', suggest a lure related to medical information to entice users to click.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/award?keyword=deficiencia+de+vitamina+b12+tratamiento+pdf
    • http://1yamal.space/74807712943w84qw.pdf
    • http://realnoe-obshenie.online/57876166197c6dyt.pdf
    • http://matras-24.ru/33513370916s7yld.pdf
    • https://xapenivivafozeb.weebly.com/uploads/1/3/1/3/131379266/pubob.pdf
    • http://xedeporib.medianewsonline.com/st_croix_greenfield_pellet_stove_cost.pdf
    • http://edarudost.online/large_pencil_pouch_amazoneq5pz.pdf
    • https://jagunafine.weebly.com/uploads/1/3/4/3/134363358/nomotivusos_gedukew.pdf
    • http://sbrf.link/pirenitjue6p.pdf
    • https://gugekomu.weebly.com/uploads/1/3/0/9/130969097/e1cf2acdee168a.pdf
    • http://jewogipuwivi.medianewsonline.com/povuxegubo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://77bac38d-831a-46d6-8f22-d7743fcadc58.filesusr.com/ugd/5b9a87_cab216fcfeee41429379e77d9016bee6.pdf?index=true
    • https://uploads.strikinglycdn.com/files/da198372-3717-43b0-8ec3-9367be2c40b7/how_to_do_mind_maps_for_studying.pdf
    • https://85fc0914-20e3-4f1c-be8c-de7e6f89f47e.filesusr.com/ugd/a44510_55f7ae7036f8452598d68567e8cad630.pdf?index=true
    • https://uploads.strikinglycdn.com/files/42161f14-97a7-4408-89e5-4f18dcbc95e4/3930851246.pdf
    • https://e0220c8c-c322-4c33-af83-7c5b0fe00b66.filesusr.com/ugd/a771bd_9767055a288c449381fb12c44e9dc924.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b1e88d4f-27ac-44ee-8621-381ebec2ac38/96570770298.pdf
    • https://1b6fe947-be7e-4494-9a94-f566f178d3d1.filesusr.com/ugd/89064d_4d03afe8c4464cb386195cfb18de0eb0.pdf?index=true
    • https://a7da3e60-63c8-46c1-a846-eab7df628ed2.filesusr.com/ugd/bba345_4054d891b9f743e5b1404a91a640671e.pdf?index=true
    • https://fa53e508-d88d-41cb-897c-7a5b6f1bfcc3.filesusr.com/ugd/361045_59f84b0eaac24ca6939c451497ed3509.pdf?index=true
    • https://0633afab-057d-4448-85e1-ac1a97571725.filesusr.com/ugd/66920c_0988e05a3d254e43a261a9349da351ec.pdf?index=true
    • https://f8d82b49-d438-4da2-b906-f876cb6fe635.filesusr.com/ugd/12dc78_81bfeebdf78e49eabe34b67d6b99e58a.pdf?index=true
    • http://saluwagasa.onlinewebshop.net/nd_kapoor_business_law_book_download.pdf
    • https://80f75f89-a1e3-4611-a0ef-7a704eb82da9.filesusr.com/ugd/0286dd_f26ed733a6cf44a4b3962044e9d71b66.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f63d.bin
c780fe54dde0e3db19233683da1705eda543103f30d20088e73b1f0117875b58
pdf-font-stream PDF embedded font (sfnt) at offset 0xF63D 5472 bytes
font_01_sfnt_off000108d9.bin
2444cdc699d3ece4d9166b07fa62c421fc3e2c6ca723250942341706f6749d75
pdf-font-stream PDF embedded font (sfnt) at offset 0x108D9 12268 bytes