Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a0d52a6773eaa5d…

MALICIOUS

PDF

72.8 KB Created: 2021-03-28 17:06:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0786f0ded55f452892608529858495b3 SHA-1: 7b4f215e1ed73c58a481c4a9f5864e6b1f3a2821 SHA-256: 7a0d52a6773eaa5d8d127ae8a23cd87c209a9b34e9b318107b6aa6a9b0df2b43
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. One prominent URL, https://vilenefex.ru/123?utm_term=arjun+reddy+ringtone++bgm, is embedded within the document and likely serves as a lure. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing or trojan PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=arjun+reddy+ringtone++bgm
    • https://static.s123-cdn-static.com/uploads/4408601/normal_5fcb5a3d174ff.pdf
    • https://sabexezoguge.weebly.com/uploads/1/3/1/4/131483217/9ba6815565.pdf
    • https://static.s123-cdn-static.com/uploads/4393754/normal_5ff95689c60a9.pdf
    • https://mozibidu.weebly.com/uploads/1/3/4/7/134763316/soraferufa-supalogufupido-vabigidozijuxiz.pdf
    • https://static.s123-cdn-static.com/uploads/4420250/normal_5fec51f632ab5.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://37e79482-e567-4eff-b449-6ea9b90d4679.filesusr.com/ugd/cff0cd_94398a1c203a4d2bb20985c5fe1a96ef.pdf?index=true
    • https://s3.amazonaws.com/votawawo/sojobunu.pdf
    • https://s3.amazonaws.com/bitizopovopaso/38180793812.pdf
    • https://uploads.strikinglycdn.com/files/67826de7-1ddd-4f08-b47e-a7506fa9046f/husqvarna_350bt_leaf_blower_review.pdf
    • https://uploads.strikinglycdn.com/files/ab953821-b49b-4756-a0ac-5a410b761b2d/gisivivoluwawifoxiwuse.pdf
    • https://uploads.strikinglycdn.com/files/4bb4517d-9a54-4014-9a48-f56b6f616a37/tatevakawadazupuzikogoruz.pdf
    • https://s3.amazonaws.com/zasepo/noguxe.pdf
    • https://s3.amazonaws.com/jikopot/kamajovutexerosasoxubu.pdf
    • https://uploads.strikinglycdn.com/files/ee95f4d5-fa38-4325-8dff-41be401662b4/52573571099.pdf
    • https://9cf5cc10-3c2e-4e30-ae6b-73ed7beed88a.filesusr.com/ugd/5c2b46_c32c002ecaa14d97b34d5df18ae210a9.pdf?index=true
    • https://1618b3f4-dcc0-4047-a816-eeb1cbe43c51.filesusr.com/ugd/a01749_e251ae8174874c7b878a1399eb5d5c2c.pdf?index=true
    • https://uploads.strikinglycdn.com/files/538e5434-1eb5-41a3-a053-0dd4d293f48b/xatol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cde5.bin
127b44c9f93874c96d25eb7ddc4688780d8877ce931cf296363fb5748d8d514b
pdf-font-stream PDF embedded font (sfnt) at offset 0xCDE5 6744 bytes
font_01_sfnt_off0000decc.bin
792a723fda6beb0aba2a5eda3ad9543608bca8d3660a1291ea418567ecb95244
pdf-font-stream PDF embedded font (sfnt) at offset 0xDECC 5032 bytes
font_02_sfnt_off0000efe4.bin
0c1b38f548d1b001b0572117daa97ddd8b19b38f8933357764d7c20b4e47c978
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFE4 10536 bytes