Malicious PDF — malware analysis report

Static analysis result for SHA-256 73b854af69b9fa29…

MALICIOUS

PDF

83.0 KB Created: 2021-03-25 17:36:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 943be66118ebac3d9e4c53dd8a16a658 SHA-1: 97281928bb458667b3de6d139d971bc054605c68 SHA-256: 73b854af69b9fa290ed163d7c5a3651ad51c1e12e3e83e18f756109696005766
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one heuristic specifically identifying a 'PDF_SEO_LINK_FARM'. The primary malicious URL identified is dafemum.ru, which is likely used to host phishing content or further malicious redirects. ClamAV detection as 'Pdf.Phishing.Trojan' further supports a phishing or malicious content delivery intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=caphras+stone+extraction
    • https://nulivuxod.weebly.com/uploads/1/3/0/7/130776854/viximapevez_nabitur.pdf
    • https://giridoxaxe.weebly.com/uploads/1/3/4/7/134703098/8f9a8f5709e28c0.pdf
    • https://wuwuleli.weebly.com/uploads/1/3/1/3/131398564/566766.pdf
    • https://dutosagow.weebly.com/uploads/1/3/0/7/130775111/7995879.pdf
    • https://tedajurilazunu.weebly.com/uploads/1/3/0/7/130739962/ribewerutizefog_mexokajejefixen.pdf
    • https://ragusixiseditof.weebly.com/uploads/1/3/0/8/130814169/nitako.pdf
    • https://cdn.sqhk.co/puxitika/eVpWgeN/wafetimakuvuxibotetata.pdf
    • https://sagagokibifaku.weebly.com/uploads/1/3/4/6/134625973/rebajuvox_vetuzogovujuvi_fatofu_meraxeraguwad.pdf
    • https://cdn.sqhk.co/nuvexajamu/BgcUbh8/gpisd_skyward_login_garland.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/200b82aa-092a-47e4-a181-2015f34be4b3/dictionary_of_literary_terms_by_martin_gray_free_download.pdf
    • https://uploads.strikinglycdn.com/files/61117b69-100b-4073-bd49-07109e14cdbf/5785063623.pdf
    • https://uploads.strikinglycdn.com/files/02eb92d2-8abd-4fa3-98da-0ca43b19e4a2/kogepade.pdf
    • https://s3.amazonaws.com/labitajaxatufib/how_to_play_the_guitar_beginners.pdf
    • https://s3.amazonaws.com/dojonuta/35605453254.pdf
    • https://uploads.strikinglycdn.com/files/6d499bf6-aab8-49ac-9708-eb1e3e8837bc/good_healthy_food_to_lose_weight_fast.pdf
    • https://s3.amazonaws.com/vifusupegiza/slideshow_powerpoint_template_free.pdf
    • https://uploads.strikinglycdn.com/files/63166848-4787-443a-9608-e2d185ae277c/jolasiba.pdf
    • https://uploads.strikinglycdn.com/files/edd5b7dc-1a6c-44df-ab28-ea86a870f1f3/how_to_use_hisense_aircon_remote.pdf
    • https://uploads.strikinglycdn.com/files/5ce9e6ff-4bdc-4a0c-8e0e-6a7ee20760b6/69243155274.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f873.bin
3602c8ec9342ba02e134e907829bfbb311fa391ee1e85cb435e742e943d31f4a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF873 3540 bytes
font_01_sfnt_off0001053c.bin
d258461abb44ca323bd12be58b732b40fa7528ff8abf010f0577157b129c6a5f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1053C 4964 bytes
font_02_sfnt_off00011617.bin
84b8667742bc3e41d9eaea50028f0c9d7f53d2cb66d421d3fdf317778fdd2722
pdf-font-stream PDF embedded font (sfnt) at offset 0x11617 11352 bytes