Malicious PDF — malware analysis report

Static analysis result for SHA-256 71348b61c7feac9a…

MALICIOUS

PDF

78.8 KB Created: 2021-03-19 20:28:21 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f8d1d695ca7dec5c06b3cd31c9cd3998 SHA-1: 6edd87cdf8a6afc82d798db22eefa94dd66733a3 SHA-256: 71348b61c7feac9a7f39e76d7db8c9caeceb227e4cafae42ac5a4d50c60b9452
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous embedded URLs, with a significant number pointing to external PDF files, indicative of a link farm. The heuristic 'PDF_SEO_LINK_FARM' specifically highlights this behavior, suggesting an attempt to manipulate search engine results or distribute malicious content. The ClamAV detection and ML classifier further confirm its malicious nature, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=joker+leaked+script+ending
    • http://zakosemej.mypressonline.com/62287937278.pdf
    • https://leditolovon.weebly.com/uploads/1/3/2/6/132682688/201210.pdf
    • https://jonomivebotuw.weebly.com/uploads/1/3/4/6/134683751/85b87e.pdf
    • https://werevofapopaja.weebly.com/uploads/1/3/4/4/134492388/dubasojixixekajux.pdf
    • http://mapugukabazewu.scienceontheweb.net/dell_optiplex_790_desktop_specs.pdf
    • https://legorigerelok.weebly.com/uploads/1/3/6/0/136056749/7742225.pdf
    • https://tidijerovapo.weebly.com/uploads/1/3/4/3/134342207/2621913.pdf
    • http://gadetebes.sportsontheweb.net/kofasutizivotudadewuta.pdf
    • https://nusutaligufobam.weebly.com/uploads/1/3/5/3/135393176/xiwokupujila_bafaf_josimudizebu.pdf
    • https://pivazadigemeza.weebly.com/uploads/1/3/4/6/134642233/babetoziliwolog.pdf
    • http://lowabunuzoxa.getenjoyment.net/how_to_recharge_ge_water_softener.pdf
    • https://sabovewedasujak.weebly.com/uploads/1/3/4/4/134493104/xivirafofaz.pdf
    • https://wufezaju.weebly.com/uploads/1/3/0/7/130738917/2865520.pdf
    • http://xumupizaxuto.scienceontheweb.net/how_to_turn_alarm_off_on_timex_watch.pdf
    • https://fepuluji.weebly.com/uploads/1/3/4/8/134871890/db2181cf09.pdf
    • https://bigakajufejala.weebly.com/uploads/1/3/4/2/134265656/fosoposojomi.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zodiripek.myartsonline.com/nyc_doe_school_calendar_2020_19.pdf
    • https://78ee58ad-4251-4cb6-9d9e-6f806931ac90.filesusr.com/ugd/b6b4e8_cf76ea14b8f14ff189b3e0ce47bb71ed.pdf?index=true
    • http://pikaderobiw.atwebpages.com/bexokike.pdf
    • https://e4da1597-3bb3-488b-9226-7c2c9e06e9ce.filesusr.com/ugd/db5d73_cfd2cfefd4894c44a8b6b0f75f272356.pdf?index=true
    • https://e082b6be-64c0-45f6-a8ff-82b9c6f476f0.filesusr.com/ugd/1479de_a739ab516976415f85a4bac7b5ea7d38.pdf?index=true
    • http://wewamamewiler.atwebpages.com/40677615933.pdf
    • https://ca108e69-7b6b-43f0-8f16-d96ebeb8a33d.filesusr.com/ugd/79e0dc_e059574f2f5d40d59c61bdb9b2e23e47.pdf?index=true
    • https://5e54d98c-4257-4cc7-9010-48f3df296eb2.filesusr.com/ugd/05240c_50e9185ed37747d98de90e0ac8572b42.pdf?index=true
    • http://wawikoduvebakap.onlinewebshop.net/rivafugolurakoj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f614.bin
5ad9977c6040bf4dd727d6d0edc354311d2ca93a6a126e5500ba3444f4f3a5e0
pdf-font-stream PDF embedded font (sfnt) at offset 0xF614 5292 bytes
font_01_sfnt_off0001082a.bin
1449cd890127c986b236fb59d35d6802527ad11243e5e8c297bdce4daab9dc3c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1082A 10500 bytes