Malicious PDF — malware analysis report

Static analysis result for SHA-256 75324f60e616ece8…

MALICIOUS

PDF

109.1 KB Created: 2021-04-04 11:20:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-08-20
MD5: b2702ab82b491e6c54bac2fbd51f78a6 SHA-1: c846552d915a218b289916dfdbb3f2124a5ab656 SHA-256: 75324f60e616ece852dc4b8159fda2f15e60bfed0f232cbeaa27173e5ca1036a
236 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file exhibits characteristics of a phishing lure, employing multiple heuristics related to SEO link farms and fake encrypted document views. It contains numerous external links, many of which point to redirector domains like 'leonvi.ru' and 'bigops.fun', suggesting an attempt to direct users to malicious content. The ClamAV detection and ML classifier further support its malicious nature, likely serving as a downloader or redirector for further stages of an attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9977

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • Fake encrypted/secure-document view lure high SE_ENCRYPTED_DOC_LURE
    Document claims to be an encrypted or protected file that must be opened through a 'secure view' link, and the action link uses deceptive infrastructure. This is the secure-document credential-phishing carrier: the page imitates a secure-mail / document-cloud gate while the link leads to a harvesting site. action link to abused redirector.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/strik?utm_term=how+to+remove+drm+from+m4p PDF link annotation
    • http://bigops.fun/is_warcraft_3_reforged_worth_buyingpxqil.pdfIn PDF document text
    • https://xirofagoxo.weebly.com/uploads/1/3/4/5/134576207/d1629dc.pdfIn PDF document text
    • https://wirosumarot.weebly.com/uploads/1/3/1/3/131398493/xilivogekaxan.pdfIn PDF document text
    • http://sell-toclick.online/23991222597azcr4.pdfIn PDF document text
    • http://bigmagazin.xyz/poxagawhcnax.pdfIn PDF document text
    • http://natur-green.fun/literatura_indigenista_peruanagnrwu.pdfIn PDF document text
    • https://zemutixo.weebly.com/uploads/1/3/4/8/134865820/zupotomiwaxu_mobebokig_fexifib_wogevufelak.pdfIn PDF document text
    • http://mikrotikwizard.com/what_type_of_oil_does_a_2013_chevy_malibu_takeiolzq.pdfIn PDF document text
    • http://voicebftyi.com/athens_tech_nursing_intent_formglzss.pdfIn PDF document text
    • http://yewes.space/singer_503a_for_sale88ypa.pdfIn PDF document text
    • https://jukonejidar.weebly.com/uploads/1/3/4/8/134876273/6034793.pdfIn PDF document text
    • https://mejoraxu.weebly.com/uploads/1/3/1/3/131380998/9818662.pdfIn PDF document text
    • http://tularobumof.66ghz.com/lagu_man_ana_mohamed_tarek_metrolagu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/gogonof/english_test_for_beginner_level.pdfIn PDF document text
    • http://jilufadipubo.epizy.com/xabununopufazamimiji.pdfIn PDF document text
    • https://s3.amazonaws.com/ritoma/bonnet_roof_information.pdfIn PDF document text
    • https://s3.amazonaws.com/loranoduzuja/batman_a_death_in_the_family_summary.pdfIn PDF document text
    • https://s3.amazonaws.com/jodabiladezot/40964435600.pdfIn PDF document text
    • https://s3.amazonaws.com/leributafa/free_homophones_worksheets_2nd_grade.pdfIn PDF document text
    • http://gatapin.rf.gd/18668623054.pdfIn PDF document text
    • https://s3.amazonaws.com/lonozote/romeo_y_julieta_1875_bully_review.pdfIn PDF document text
    • https://s3.amazonaws.com/xufujofaleki/como_se_calcula_la_normalidad_de_una_solucion_de_acido_sulfurico.pdfIn PDF document text
    • https://s3.amazonaws.com/rurovikejigibu/43596020554.pdfIn PDF document text
    • http://zuvujivir.rf.gd/7632656377.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00015794.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15794 2960 bytes
SHA-256: 3a99bfcc8a6322cb1f5d9dd0c76c95525b0630114fc12c53a342d41e6b6e0e01
font_01_sfnt_off00016204.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16204 4604 bytes
SHA-256: f9488b9fd2fe9ade3f282179c23666f081bce4fb05e8d246317f9ce06788bd90
font_02_sfnt_off000171c1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x171C1 11400 bytes
SHA-256: 774781beed00626fa000d1c7ef9cc40d3111061f2841194819c9e1e021b9ba1b
font_03_sfnt_off0001987b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1987B 4324 bytes
SHA-256: 9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2