Malicious PDF — malware analysis report

Static analysis result for SHA-256 77d33a56b71ebaff…

MALICIOUS

PDF

69.0 KB Created: 2021-03-30 13:44:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 51ac041556d20c4a3a966c0123ca5fd5 SHA-1: 1e78cac41cffeb4bf2bd000f2f2be1892dfb4198 SHA-256: 77d33a56b71ebaffa8344da1a9124f843069d84a639bc74d9869310c6ecc414f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, with one prominent URL pointing to a suspicious domain. ClamAV also detected this file as a phishing trojan. The presence of numerous external links suggests an attempt to redirect users to potentially malicious content or to manipulate search engine results.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7003

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/strik?utm_term=what+happened+to+percy+jackson+in+the+son+of+neptune
    • http://load-bcp.com/sony_vaio_operating_system_not_found_after_bios_updateamf01.pdf
    • http://4338bacchus.com/abcd_movie_all_song_320kbps6jjhe.pdf
    • http://thefortykuti.com/jadeposotukeritirm68p2.pdf
    • https://voxivunesiru.weebly.com/uploads/1/3/1/4/131407918/xijupoda-satozo-mejakuv.pdf
    • https://cdn.sqhk.co/dijogiper/mrAiciL/53756667777.pdf
    • https://cdn.sqhk.co/wakunexigoto/RmExjfK/billy_joel_my_life_sheet_music.pdf
    • https://cdn-cms.f-static.net/uploads/4451376/normal_60341691f2628.pdf
    • http://mnatural.space/ball_mayhem_unblocked_games_76dw1ai.pdf
    • https://gitapizi.weebly.com/uploads/1/3/2/6/132683136/zupug.pdf
    • https://dazutexigamufo.weebly.com/uploads/1/3/2/7/132740900/3451206.pdf
    • https://cdn-cms.f-static.net/uploads/4453335/normal_60150eb0bc90f.pdf
    • https://cdn-cms.f-static.net/uploads/4373502/normal_6049b8babf2ae.pdf
    • http://misstourist.info/32560635887kmmg5.pdf
    • https://cdn-cms.f-static.net/uploads/4494891/normal_60108e1d722b7.pdf
    • https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/20902d900ed9e0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/timeziso/fejuko.pdf
    • https://b70645e9-42d7-44c6-80f2-f165c8819e8d.filesusr.com/ugd/3f1130_c3ae063e96ff4ea4b009a03a07ca3fac.pdf?index=true
    • https://s3.amazonaws.com/dekogamik/fosroc_expandafoam_sheets.pdf
    • https://s3.amazonaws.com/gimisorixosu/navy_test_pilot_school_aircraft.pdf
    • https://s3.amazonaws.com/litunux/munizaziba.pdf
    • https://c8019651-2137-4367-b38e-775fff3f8a75.filesusr.com/ugd/fc5a02_c4281634d38a409bb78938fd45721caa.pdf?index=true
    • https://74a5c9af-61bb-4d76-9351-4d02c0bf652a.filesusr.com/ugd/e33828_1507835fa6c04bf5977078a7f921f4a7.pdf?index=true
    • https://s3.amazonaws.com/lanaladu/boy_girl_clipart.pdf
    • https://9849c7ec-8b19-4b81-9a64-db2537ea7c40.filesusr.com/ugd/97b1c0_d0826e0b40f24a269d3302a889e0a98d.pdf?index=true
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e981.bin
70f8c191e9a61d229e7a6c4af7e834735bf6bbf4c99d5a8044d0865e30b53cf1
pdf-font-stream PDF embedded font (sfnt) at offset 0xE981 5464 bytes