Malicious PDF — malware analysis report

Static analysis result for SHA-256 70382294d9d92c08…

MALICIOUS

PDF

81.0 KB Created: 2021-04-29 12:48:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ab6ebf66220e87b62072be7804cfc182 SHA-1: 7b99394324d3c95ffc6b383d9dcc8692ec5755e2 SHA-256: 70382294d9d92c089261e6266cf8c38dc4ee89f0e2e7101af33eee924fa04043
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing or trojan threat. It contains a large number of external links, many pointing to other PDF files, suggesting a link farm or redirection mechanism. The embedded content, though obfuscated, appears to reference printer manuals and application details, likely serving as a lure to direct users to malicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=hp+photosmart+c7200+manual
    • https://static.s123-cdn-static.com/uploads/4388420/normal_5fefc155984e3.pdf
    • https://cdn-cms.f-static.net/uploads/4377379/normal_600f8f97e0a3a.pdf
    • https://static.s123-cdn-static.com/uploads/4410459/normal_5feff5b502849.pdf
    • https://cdn.sqhk.co/reravarev/zhihbid/kusubiwuguvixedireji.pdf
    • https://lopatitegadusi.weebly.com/uploads/1/3/5/3/135311006/6820036.pdf
    • https://zogewuvenofo.weebly.com/uploads/1/3/2/6/132683334/b1eb1c98312ca69.pdf
    • https://cdn.sqhk.co/mogizilo/jjifii3/28307992432.pdf
    • https://cdn-cms.f-static.net/uploads/4383445/normal_6036787f1747b.pdf
    • https://cdn.sqhk.co/pozusonitid/jUidjax/56529253827.pdf
    • https://cdn.sqhk.co/nutewakizi/jdJhgOc/bloodsport_original_movie_poster.pdf
    • https://mewotetinud.weebly.com/uploads/1/3/5/9/135956813/f8330503df63.pdf
    • https://fubomagasikeka.weebly.com/uploads/1/3/4/4/134474343/pamut_mugulopo_bizutodesube_nuzukakoraj.pdf
    • https://vifapuxup.weebly.com/uploads/1/3/4/0/134018045/51d4a7.pdf
    • https://static.s123-cdn-static.com/uploads/4454161/normal_5fff988da6b9e.pdf
    • https://cdn-cms.f-static.net/uploads/4386080/normal_6019bd98e8f8a.pdf
    • https://static.s123-cdn-static.com/uploads/4449769/normal_5fc71cdca901f.pdf
    • https://cdn.sqhk.co/zufuxirap/Z5K0eug/fobamuzejojowaxabubuf.pdf
    • https://cdn-cms.f-static.net/uploads/4375194/normal_60226f81a5ade.pdf
    • https://serabonileraso.weebly.com/uploads/1/3/4/4/134444783/4173541.pdf
    • https://static.s123-cdn-static.com/uploads/4368989/normal_5fca4c885d4f2.pdf
    • https://cdn.sqhk.co/vavewiren/jazhfhj/377371315.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9b9.bin
1ffb53e0e0de1c37ab7cb0afb3d5407e0a6655a3c43b8785565fb3ddf1c74094
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9B9 5488 bytes
font_01_sfnt_off0000fc3a.bin
578e73be6472fea1de5913ded35f1e8ddbb16619e29f9a681319e98f00f91c85
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC3A 10604 bytes
font_02_sfnt_off000120d3.bin
a4f616c8ed03231f927c8f6725ddfb6aed79ba1e9c0c9257d690ec40f184d4cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x120D3 16388 bytes