Malicious PDF — malware analysis report

Static analysis result for SHA-256 7272df5a1ebb82c6…

MALICIOUS

PDF

82.3 KB Created: 2021-03-30 10:31:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e28bbc8a846e07758dac04e00b5f0836 SHA-1: 4ba759a44999890451da984e43af8bdd14dadbd7 SHA-256: 7272df5a1ebb82c65a9cf18a5e7824fe754eb35b6c08441b063cfc3e00642128
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for phishing or directing users to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting an attempt to manipulate search results or distribute content across many domains. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://zajinet.ru/wix?keyword=eligibility+manual+for+school+meals+2020
    • http://sayseedokg.com/cfa_level_1_practice_questions20oiu.pdf
    • https://vugilove.weebly.com/uploads/1/3/4/2/134234765/7941482.pdf
    • https://raguwagoneneza.weebly.com/uploads/1/3/1/3/131384547/339776.pdf
    • http://it50life.pro/download_drag_sim_2018_mod_apklb98z.pdf
    • https://devudupaf.weebly.com/uploads/1/3/4/8/134880603/8da0033.pdf
    • https://wirolarem.weebly.com/uploads/1/3/1/6/131636642/435633.pdf
    • https://vomimefime.weebly.com/uploads/1/3/5/3/135316042/xolapagogama.pdf
    • https://menolalosixoj.weebly.com/uploads/1/3/4/7/134714047/sagum.pdf
    • https://vowufesoval.weebly.com/uploads/1/3/4/8/134885018/sonaxowexinoz.pdf
    • http://vorecan.fun/fagilibiwovikoj1u9n.pdf
    • https://foxejakepi.weebly.com/uploads/1/3/0/8/130874264/9746308.pdf
    • https://nobakunifiximup.weebly.com/uploads/1/3/5/3/135310199/e3bb92521.pdf
    • https://bifimazetaxa.weebly.com/uploads/1/3/5/3/135326975/09d55379745b9c3.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://0926596c-b1e6-4473-87d6-fed2e709bfeb.filesusr.com/ugd/e2a635_a50933d03d0d4c7ea2c63f27992a5a92.pdf?index=true
    • https://s3.amazonaws.com/tigovatolis/75046649539.pdf
    • https://s3.amazonaws.com/limewub/web_browser_history_on_android_phone.pdf
    • https://98be45bc-63b9-4117-aff7-84a3d4f2c4a0.filesusr.com/ugd/90c678_12205ac98561473b9a64e1b096d179fc.pdf?index=true
    • https://s3.amazonaws.com/sebunuzu/43729563543.pdf
    • https://s3.amazonaws.com/jebokizez/cdc_healthcare_associated_infections_progress_report.pdf
    • https://s3.amazonaws.com/jasadavebaga/zilipiviriz.pdf
    • https://s3.amazonaws.com/jojitagifuva/2d_animation_programs_android.pdf
    • https://s3.amazonaws.com/xukanomarexumu/nedexuvuji.pdf
    • https://19a39513-20cc-49d1-a75c-e30ce0314142.filesusr.com/ugd/f99735_32f85ca0ca3f4a949d77c4a1f96eb0d3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb97.bin
f95766254e7f4f1774a42819f7af3856cde6b8d94a717184597fa7a14e876079
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB97 5768 bytes
font_01_sfnt_off0000ff23.bin
556f7ec70733cb6ac6c39258df91786e895ea49788f745bc438524d89f1ae5f8
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF23 10796 bytes
font_02_sfnt_off00012456.bin
a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x12456 16204 bytes