Malicious PDF — malware analysis report

Static analysis result for SHA-256 79914c6a7e4d765b…

MALICIOUS

PDF

82.6 KB Created: 2021-03-10 15:43:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dfd43776c0ad20dc4d12850a706659b4 SHA-1: 5e4e931df2a01d4d38ad03e20d0c1a602f9c2061 SHA-256: 79914c6a7e4d765bb38225b31683d74ca79420a6188fbce77fbb2072240dc475
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. One of these links, 'https://soxebez.ru/aws?utm_term=best+mods+for+silent+hunter+3', is flagged as malicious. The presence of numerous external links suggests an attempt to direct users to potentially harmful or deceptive content, aligning with phishing or SEO abuse tactics. No scripts were extracted, but the PDF structure itself facilitates the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/aws?utm_term=best+mods+for+silent+hunter+3
    • http://sagadutotituvop.22web.org/best_audio_booster_android.pdf
    • https://cdn.sqhk.co/petebeki/eegiZjb/king_s_throne_game_of_lust_review.pdf
    • http://kuzuwagakemesux.iblogger.org/vatirozusezoviwomexezanin.pdf
    • http://badodamibevije.iblogger.org/raxopuxedojotumemo.pdf
    • https://cdn.sqhk.co/rokajoten/JQicid3/pictoword_level_333.pdf
    • https://cdn.sqhk.co/tuxonewebuke/gifhaSe/fivazuremiwumasonon.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2179f78f-0fdc-42f0-8e60-e0e8c56cf8e8/how_to_sit_to_relieve_knee_pain.pdf
    • https://s3.amazonaws.com/gopuze/zavafonix.pdf
    • https://uploads.strikinglycdn.com/files/f21941ef-ac8c-4585-bab6-cd095d1532de/15610648425.pdf
    • https://05790d5e-93e9-4545-bcc4-99c37f081c18.filesusr.com/ugd/bff4d5_a963dc323cb64a8698d19257f0e7a194.pdf?index=true
    • https://s3.amazonaws.com/marimejerebo/nidopebitimi.pdf
    • https://s3.amazonaws.com/takateg/java_jdk_and_jre.pdf
    • https://s3.amazonaws.com/dudurat/jolef.pdf
    • http://rasovofux.epizy.com/el_caballero_de_la_armadura_oxidada_preguntas_y_respuestas_capitulo_3.pdf
    • https://s3.amazonaws.com/fuzafuzeruwit/natolirizanedufosezufu.pdf
    • https://s3.amazonaws.com/divikufifir/mawagekakezop.pdf
    • https://uploads.strikinglycdn.com/files/c7d462a3-ebd3-4c93-8d91-d2005c224a1f/vuzumi.pdf
    • https://s3.amazonaws.com/benubapopikaj/3332851886.pdf
    • https://db6d201d-bdff-4648-9982-d9cfaac7639e.filesusr.com/ugd/98857b_9e6acc7029c74fd5bb73c9ce51d0087d.pdf?index=true
    • https://s3.amazonaws.com/rotowan/australian_dietary_guidelines_for_adults.pdf
    • https://uploads.strikinglycdn.com/files/dbf6e75c-fbd9-4ff0-afe8-ccfc4289fa76/what_is_a_turning_point_in_a_story.pdf
    • https://s3.amazonaws.com/libusamagowuvo/2927039258.pdf
    • https://s3.amazonaws.com/towakog/liwow.pdf
    • https://de99c131-68bf-4271-bcef-cda292486844.filesusr.com/ugd/f5892c_97cfbfd7c1a543ac969904ec818a5683.pdf?index=true
    • https://uploads.strikinglycdn.com/files/6073e2e9-f07c-472a-b73a-6392a299e5e2/kitofijutuxapaji.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010466.bin
fb39dd30c018bd790d81ae799eed1daddfa0c0ef6cfdf21d52d0227a0348531c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10466 5152 bytes
font_01_sfnt_off000115c5.bin
6b65c86bc9cddaf9d71b17a3ac970a89e0ef9127d673a6f8b1e5ec607907694b
pdf-font-stream PDF embedded font (sfnt) at offset 0x115C5 11644 bytes