Malicious PDF — malware analysis report

Static analysis result for SHA-256 7717f0fd8a56a450…

MALICIOUS

PDF

78.2 KB Created: 2021-04-17 08:34:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8413893aa139297ad892b40120eb1159 SHA-1: 9e100c13339d309cf23163fa7a70a9547ec379e0 SHA-256: 7717f0fd8a56a450b8aa3e3b46980d9e5ff7c4e73a2c737b086f958181e13bd9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a significant number pointing to potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' and 'PDF_URI' heuristics. The ClamAV detection and ML classifier also strongly suggest malicious intent, specifically phishing. The document body, though partially corrupted, contains a title related to winning the lottery, reinforcing the phishing pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=how+to+win+the+lottery+every+time+in+bitlife
    • http://instup.xyz/minha_me__uma_pea_2_filme_completo_netflix7bwn2.pdf
    • http://istlan.space/bitmap_format_headerqqb1q.pdf
    • https://falojaba.weebly.com/uploads/1/3/0/7/130776150/4209387.pdf
    • http://xofazonir.iblogger.org/maxiz.pdf
    • https://sirowatogiwu.weebly.com/uploads/1/3/2/8/132814809/5934eb4037.pdf
    • https://vavetoros.weebly.com/uploads/1/3/4/8/134854671/bd33d897adb548.pdf
    • https://kotezoxeruv.weebly.com/uploads/1/3/5/3/135345651/pekoz-xuginizimijom-pozemekarawas-nolika.pdf
    • http://javiwovaxaduza.22web.org/julius_caesar_english_translation.pdf
    • http://italia-doc.fun/inference_worksheets_for_grade_5ph6sv.pdf
    • https://xaripapaxogazix.weebly.com/uploads/1/3/1/4/131437161/dinavow-fufapafosufafop.pdf
    • http://sowaviwexurejo.22web.org/bapidilaw.pdf
    • http://netewe9.xyz/sosikamivosijesaxuvitf5xxf.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/52fd6fdd-8e90-4a4b-baf5-ada2aea37b6f/plan_y_programa_de_estudios_2011_primer_grado.pdf
    • https://uploads.strikinglycdn.com/files/cdcd4715-bd2e-455e-86d1-400a871f15f1/tomukovulid.pdf
    • https://uploads.strikinglycdn.com/files/6fe4bb3a-a4c3-4923-b26e-a2f5d8af1f14/ratorunovukeroxubu.pdf
    • https://uploads.strikinglycdn.com/files/74e6217e-832b-49e7-888f-8ba8973ac15a/how_to_change_resolution_on_iphone_8_camera.pdf
    • https://3dd85f33-233b-4b3c-8e53-142bc8307eec.filesusr.com/ugd/8df890_6197ca1d12cc41b88d0cb06c3e2636c9.pdf?index=true
    • https://4f65703b-d4c0-4c9c-9e30-73c8cc83ec5d.filesusr.com/ugd/54fa57_61b29c9881b34b1b9e7636d647f2066d.pdf?index=true
    • https://73e25548-3913-4bbb-aa69-a1b25f69568d.filesusr.com/ugd/cece23_9357cdc08ae040498fc279d17eccf93c.pdf?index=true
    • https://e5720c39-3c1c-4a52-9be9-509675281b5a.filesusr.com/ugd/0010c8_15416729a99848b7b5747ebd9e47ff86.pdf?index=true
    • https://uploads.strikinglycdn.com/files/67b97d3d-09d0-4941-8130-9156fef477fa/40524670003.pdf
    • https://f19d2187-ce67-4d04-8798-eef694565169.filesusr.com/ugd/bd4746_cc8a8318ad50494d9ea7a42097854404.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f473.bin
51e7c0fb508b950207fd030941e393b6b6813ef2a64756acf14818c50c574b52
pdf-font-stream PDF embedded font (sfnt) at offset 0xF473 4972 bytes
font_01_sfnt_off0001054d.bin
def27251ce3e67016936a738bf1459a42306a2021b8ccd67089b850c89164a21
pdf-font-stream PDF embedded font (sfnt) at offset 0x1054D 11052 bytes