Malicious PDF — malware analysis report

Static analysis result for SHA-256 7676dfc20824fbda…

MALICIOUS

PDF

86.6 KB Created: 2021-04-08 00:54:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5e6cf9d4765bd9ebf7fc84ee93cbad52 SHA-1: d81e9ddcf011897aacb195ee2057c113addb91ed SHA-256: 7676dfc20824fbdaf8ffa0d64f523b78bcf37502a3c2118a878aa6608c8d5670
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF contains numerous external links, with a significant number pointing to potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' and 'PDF_URI' heuristics. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware delivery. The presence of 'LOLBin token sequence' and the overall structure point towards an attempt to exploit vulnerabilities or trick users into visiting harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=percy+jackson+sea+of+monsters+book
    • http://labincom-med.ru/datebat82qt9.pdf
    • http://miiliioner.xyz/curling_irons_sizes_guideqoika.pdf
    • http://sqrab.top/509426559357k3rt.pdf
    • http://leaninrzpd.site/city_of_stars_sheet_music_musescoretrtmn.pdf
    • http://quickstore.pro/zugelajufotaxowunuvufsyant.pdf
    • https://uploads.strikingl
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/dd904e98-f2b3-457a-a6be-dd3d66dc455b/botadudema.pdf
    • https://uploads.strikinglycdn.com/files/256f5ece-1753-4970-af78-4fc8dc68d637/wosepegegakekukazuwosezuz.pdf
    • https://uploads.strikinglycdn.com/files/b3557a10-e99b-4521-af34-d3330e807450/how_do_i_find_proofreading_jobs.pdf
    • https://uploads.strikinglycdn.com/files/f87a55b7-cdb8-4836-94ea-412772a7f258/is_projectile_protection_good_in_minecraft.pdf
    • https://uploads.strikinglycdn.com/files/190265d8-b26a-4e7c-8939-0a826b880784/the_last_leaf_questions_and_answers_mcq.pdf
    • https://uploads.strikinglycdn.com/files/f96ee290-d6c0-4a2f-856e-667e643a5998/colombians_living_united_states.pdf
    • https://uploads.strikinglycdn.com/files/f2f659af-3a4f-4838-bff5-f4c782832d88/pdf_viewer_plus_se_free_download.pdf
    • https://uploads.strikinglycdn.com/files/fdd777fd-1db9-4a33-a929-5c11122a7520/76072586920.pdf
    • https://37bcb4aa-7747-4ff6-a352-0e22bf983c21.filesusr.com/ugd/4393d3_f2934b1de08845449d5b96a3a391cbf6.pdf?index=true
    • https://uploads.strikinglycdn.com/files/7e5661be-2574-42fa-9ea4-e5fee36c408f/50006914383.pdf
    • https://uploads.strikinglycdn.com/files/eca49d9a-220d-4d1b-a907-75388933e663/wildgame_innovations_terra_extreme_14mp_reviews.pdf
    • https://uploads.strikinglycdn.com/files/d424464f-1648-4a5b-9cdc-d06e1aacf9f6/what_are_the_best_times_to_eat_for_weight_gain.pdf
    • https://6d5fec37-5936-4ae8-8938-03a86e982f09.filesusr.com/ugd/d4da64_82aaacf1b56d401cbae46a6ab8815974.pdf?index=true
    • https://uploads.strikinglycdn.com/files/63274fdb-117e-4092-b71d-2ed64f548d5e/ergo_360_infant_insert_pillow.pdf
    • https://uploads.strikinglycdn.com/files/4394a28b-d27f-4b5e-a833-a81ad4df51a6/ritilu.pdf
    • https://uploads.strikinglycdn.com/files/2fb78373-36ed-4461-ac9c-59cc4769d5f2/how_much_to_install_a_ductless_mini_split.pdf
    • https://a0d2adcf-75bd-42a9-a42a-c23e1c6e9e1a.filesusr.com/ugd/85c99c_1d243671f0f94306b3fea14732fbe598.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000113a5.bin
7e6e7ffb057bb50b744e994308d764411218414c6bd3b975610ab5631b63c938
pdf-font-stream PDF embedded font (sfnt) at offset 0x113A5 5380 bytes
font_01_sfnt_off000125f1.bin
c964c8b232b98f828b74d60a5a4a1c239ed871826c86b8c3b849f847a9448e9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x125F1 11332 bytes