Malicious PDF — malware analysis report

Static analysis result for SHA-256 75b9a0b88bdf2f14…

MALICIOUS

PDF

80.3 KB Created: 2021-03-12 02:41:56 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 83a9e24e9f5f25a2e913f5a9da3b3ea9 SHA-1: e21bf5504efecae4a8018e560f6afbe49b63b082 SHA-256: 75b9a0b88bdf2f1434307a8fd51cd13d8a5e358bfde57adb99cda404639cdedd
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF contains numerous external links, many pointing to other PDF files, suggesting a link farm or redirection mechanism. The 'SE_CLICKFIX' heuristic indicates social engineering to prompt the user to execute commands, a common tactic for downloading and running further malicious content. While no scripts were directly extracted, the PDF structure and heuristics strongly suggest an exploit or downloader.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9954

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=steam++finished+but+restarted
    • https://cdn.sqhk.co/wakewafo/TF4Sqjh/dafubolusamukezenusikise.pdf
    • http://trujillostacoshop.com/candy_legends_codeszk8tq.pdf
    • https://tojuxumisadef.weebly.com/uploads/1/3/4/7/134714483/mipotes.pdf
    • http://myshoes.moscow/93504255187cbgjf.pdf
    • https://jinozeposejide.weebly.com/uploads/1/3/1/4/131453810/a1dfc6ae9.pdf
    • https://semogabetik.weebly.com/uploads/1/3/1/4/131482882/jupaduwebefilapu.pdf
    • http://tryse.xyz/97338022148dkjsn.pdf
    • https://cdn.sqhk.co/vemegunir/fqjb14m/new_english_song_2020_with_lyrics.pdf
    • https://cdn.sqhk.co/vetelojid/jYBpjd2/sporty_gran_runes.pdf
    • http://hayatevesigar.online/68608145828u4qbk.pdf
    • https://kevititexozasen.weebly.com/uploads/1/3/2/7/132712545/8a3ca830.pdf
    • http://verification-help.com/photo_collage_maker_for_iphone_wallpapervfz4k.pdf
    • https://wuwemupijebuvat.weebly.com/uploads/1/3/4/0/134012408/xazudebaxavoxif-kililisavumu-juwomarekedipi.pdf
    • https://cdn.sqhk.co/pumevigatare/adiheib/magoxefanobijeniki.pdf
    • https://cdn.sqhk.co/dagufiwus/jWWhajb/fastest_launcher_app_android.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/c7ff9ba3-9dec-4722-84fd-ebeda1332492/pelicula_el_mundo_de_sofia_en_espaol_completa.pdf
    • https://9907981b-0bc7-4fd3-a434-169f7cdadf42.filesusr.com/ugd/575363_2a8e7327fe984e7f899667988428ae69.pdf?index=true
    • https://uploads.strikinglycdn.com/files/6ddbe911-c0ce-4d37-a1b9-fd14d5cb779f/zazodoxixujimepofakoguv.pdf
    • https://uploads.strikinglycdn.com/files/703e90f5-f596-4a09-ad40-713c1e9208e8/mechanical_engineer_role_in_manufacturing.pdf
    • https://uploads.strikinglycdn.com/files/78ddc34a-1655-4a46-93fe-d32bd09d747d/xunixegelawitipod.pdf
    • https://uploads.strikinglycdn.com/files/38ee7317-d231-43af-9248-b6ec7381ff96/gefogakigedezerizofev.pdf
    • https://uploads.strikinglycdn.com/files/715389a5-6f1a-45db-bb31-e64a691e4c74/19670203309.pdf
    • https://ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com/ugd/eda9ba_7c886ffb38ce4c579c92121a2667da5b.pdf?index=true
    • https://uploads.strikinglycdn.com/files/8adcd906-9a58-4756-aae6-f9a5f7e8c34a/reif_principles_of_statistical_and_thermal_physics_f.pdf
    • https://972af30b-04c2-4618-b911-83ba0b7fef9e.filesusr.com/ugd/84a5c6_d42c13cb6a22405d967c058240417b0c.pdf?index=true
    • https://8533cbf3-c0d6-400c-bdf8-8ca38cf0242b.filesusr.com/ugd/135178_6c9874dc7bb446b39dec377655bc3d2e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/37ce7595-2806-48fd-b764-cd7f8dae9a4f/advanced_microeconomics_hal_varian.pdf
    • https://uploads.strikinglycdn.com/files/db71c593-9b4b-4e7b-b835-27e3e6d36eaa/38146294366.pdf
    • https://uploads.strikinglycdn.com/files/83a4367e-9c8b-40c6-bb69-3ad11c516c4b/xarikudag.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fbcb.bin
da374b78ebd068413c8602e9fb019a3fa42c83de68b7c8d336311c00e05f33a3
pdf-font-stream PDF embedded font (sfnt) at offset 0xFBCB 5360 bytes
font_01_sfnt_off00010dd8.bin
0f725c869667acc892f48d0d1e5364c803337b3f505abe9c140b64b139971c22
pdf-font-stream PDF embedded font (sfnt) at offset 0x10DD8 11020 bytes