Malicious PDF — malware analysis report

Static analysis result for SHA-256 7467c64329a928f5…

MALICIOUS

PDF

92.0 KB Created: 2021-03-23 01:20:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 59d800ad129d197488bc23ed7e140c2a SHA-1: de807bac7baa033d2a7f5ca8ac747c5a0b43b93b SHA-256: 7467c64329a928f54c8078f2bcb7de3a5cd3228439b96288e3535cd8fbe4fb72
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The primary URL points to a domain associated with SEO-based link farms, suggesting a campaign to drive traffic to potentially malicious or ad-filled content. ClamAV also detected this file as 'Pdf.Phishing.Trojan'. No scripts were extracted, but the structure indicates a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/123?utm_term=biographical+sketch+about+yourself+template
    • https://cdn.sqhk.co/soxesemu/VqdicMX/bibasasevonugejisidemuz.pdf
    • http://grusha.space/baxosozitigmthvm.pdf
    • http://paksorond.xyz/indian_history_books_in_kannada_language16bfi.pdf
    • https://satalediveli.weebly.com/uploads/1/3/4/0/134018026/2404822.pdf
    • http://zdorovie-vashe-vse.xyz/33409329297la14f.pdf
    • https://cdn.sqhk.co/zoxinugokas/gifVBau/sebofivunosewomu.pdf
    • https://cdn.sqhk.co/rilixuzewiv/3ja4het/instagram_followers_increase_apk_free.pdf
    • https://topudamix.weebly.com/uploads/1/3/4/5/134581811/tupexubidil_dujowa.pdf
    • https://cdn.sqhk.co/wosipuvetot/jijiicS/break_wall_game_free_download.pdf
    • https://cdn.sqhk.co/bepemuno/gfNVham/zapugilebamebemamixulo.pdf
    • https://cdn.sqhk.co/rubogomuweme/oghgfji/jio_recharge_offer_paytm_399_online.pdf
    • https://cdn.sqhk.co/zopizote/bidiaVc/34578474274.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/baposivarabuj/57564540159.pdf
    • https://uploads.strikinglycdn.com/files/1e79e250-a329-4dae-ac99-c69632c8e6eb/how_much_did_a_loaf_of_bread_cost_in_1980.pdf
    • https://s3.amazonaws.com/kovilowab/fixed_assets_account_on_balance_sheet.pdf
    • https://uploads.strikinglycdn.com/files/7c7f42ac-1ada-4b2f-b0fd-b608c938c8c6/baby_trend_jogging_stroller_replacement_front_wheel.pdf
    • https://s3.amazonaws.com/muwomapotumugi/dashboard_html_bootstrap_templates.pdf
    • https://s3.amazonaws.com/sixenogafopoj/84965733082.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011c5e.bin
1bce697ff19990730a63ad5fcd4f59a42b454c66d9b05a09cf73e56ec3a93c29
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C5E 5560 bytes
font_01_sfnt_off00012f53.bin
5add5ca0a97feb3b755ab93c22f062b3ed391062601fc62bde1b0ce72d1e9ecf
pdf-font-stream PDF embedded font (sfnt) at offset 0x12F53 11004 bytes
font_02_sfnt_off000154ba.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x154BA 4324 bytes