Malicious PDF — malware analysis report

Static analysis result for SHA-256 72e989a4e8f27487…

MALICIOUS

PDF

76.6 KB Created: 2021-03-21 23:09:07 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d2671728530fa89c6484767d1097f007 SHA-1: 5f160e6d6144cca80c21839596e3b28655841d94 SHA-256: 72e989a4e8f274874266db718faca0c63e58a362d8ad46ba6fa9d08b627f4908
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a common tactic for phishing or redirecting users to malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as Pdf.Phishing.Trojan. The document body, though heavily obfuscated, contains a query that suggests a lure to disguise the malicious nature of the links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/aws?utm_term=who+played+the+bat+boy+in+the+natural
    • https://cdn-cms.f-static.net/uploads/4420224/normal_603d7ce3bd6d5.pdf
    • https://cdn-cms.f-static.net/uploads/4414153/normal_60297126a6618.pdf
    • https://cdn.sqhk.co/pawapoma/hlhcijO/67646886730.pdf
    • http://distornyup.site/divine_intervention_in_the_odyssey_quoteskwg6h.pdf
    • http://inostrana.com/how_much_can_a_2020_ram_1500_5.7_hemi_towwghgy.pdf
    • https://cdn.sqhk.co/ropikenetu/8ghAFHd/26572305175.pdf
    • https://cdn.sqhk.co/fofodafexadu/2ORjbyf/mini_dachshund_breeders_pennsylvania.pdf
    • https://cdn.sqhk.co/wujakegu/cI3ojik/pc_games_free_download_windows_10_offline.pdf
    • https://cdn.sqhk.co/gusisezepemu/mhdrhdb/zombie_drift_mod_apk_download.pdf
    • https://cdn.sqhk.co/bujasugawo/1zC9Cjg/piwoxojetinokekep.pdf
    • http://trokot-newshop.online/10544399259qec8k.pdf
    • http://smartcreditus.info/alphabet_killer_movieml4c8.pdf
    • https://cdn.sqhk.co/wabogoga/icq5fha/59827401651.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/11462108-0a3a-424d-9f83-21259c9b5575/the_one_thing_audiobook_mp3_download_free.pdf
    • https://uploads.strikinglycdn.com/files/57469285-68ac-41f7-9cc4-064e5d22c355/24497380809.pdf
    • https://uploads.strikinglycdn.com/files/a4fcf4de-a359-4392-a5de-142cb479eef6/besaneg.pdf
    • https://2a4b29e6-a790-453e-81e7-e8b9caf2c27b.filesusr.com/ugd/bf0735_1801fe5a04b2456cb82b584bb37736f5.pdf?index=true
    • https://203e60c5-e32a-4587-ab6d-31d66de6d5b9.filesusr.com/ugd/014c36_69b177d5fc9a4b9d9cb0d70b674af1f6.pdf?index=true
    • https://uploads.strikinglycdn.com/files/f1648c6e-003a-4b13-92d2-dfdc709e6614/casti_sport_bluetooth_plantronics_backbeat_fit_3100_black.pdf
    • https://uploads.strikinglycdn.com/files/4c509eef-83a5-4500-b666-3727bcbdf5ab/geluradaxisaj.pdf
    • https://3e80c8bf-0031-4ca1-bfa9-4484641fefed.filesusr.com/ugd/08103e_95e98cd439cc442ab5f39cb8076d89e4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef3a.bin
1b27da36153a8b9f5b96f2f8cb2148d7f6c20f72face370225b8bb019cfe0c44
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF3A 5124 bytes
font_01_sfnt_off000100ac.bin
50eb0216e8378759a6921b4b30c1c2155772003c14ba253ce86db8e3715b02f6
pdf-font-stream PDF embedded font (sfnt) at offset 0x100AC 10660 bytes