Malicious PDF — malware analysis report

Static analysis result for SHA-256 7bf03e576d665583…

MALICIOUS

PDF

81.3 KB Created: 2021-04-01 00:23:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3b84080a8c7b27dc7219ce9a256a8c2a SHA-1: 7efebc0c19ab9bf6bff953afc046803fccb2235c SHA-256: 7bf03e576d665583436b14494a2d1bbb34d9cc5273b0b034bbaefc297cea14a1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for link farms or phishing lures, with one prominent URL pointing to a suspicious domain. ClamAV and ML classifiers also flagged this PDF as malicious, specifically identifying it as a phishing trojan. The presence of embedded URLs and the overall structure suggest an attempt to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/wix?keyword=college+physics+1+final+exam+study+guide
    • http://takefeduw.iblogger.org/report_taxi_driver_cape_town.pdf
    • http://vurujorifu.iblogger.org/battlefield_1_pc_size.pdf
    • http://tapikujub.22web.org/free_maths_and_english_worksheets_printable.pdf
    • https://cdn.sqhk.co/xisalaximel/jiehdnb/movie_director_simulator.pdf
    • https://cdn.sqhk.co/zikegasenar/gdvgetV/29010191060.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/fcba5d5a-059a-4fef-823c-b781f5ada101/kotevarid.pdf
    • https://850a36a1-966c-46c3-86ed-e15bcb5778a7.filesusr.com/ugd/ede58b_aa323dee4382407d8e20ec1f61187c5d.pdf?index=true
    • https://b7953657-6b45-4ea9-9d9d-f701e3f26526.filesusr.com/ugd/45996c_8cd3325549284ae4a65debfd52b4ee97.pdf?index=true
    • https://uploads.strikinglycdn.com/files/28a0c767-6af6-406a-b046-abe2209c3dac/what_is_a_good_opening_statement_for_a_resume.pdf
    • https://4f0754e2-f0c4-47db-826b-83042027646c.filesusr.com/ugd/7a11b0_e22e2abb19484f89ba33720da4057de3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/c08c71b8-2638-4f49-8fe1-917f5834ce78/nibupimesagixaxunegubu.pdf
    • https://uploads.strikinglycdn.com/files/e04eec80-7e9b-4b2a-af27-285ec2ffb6af/lasko_tower_fan_with_ionizer_troubleshooting.pdf
    • https://f7f2eb1f-4ce6-40bf-b337-6bcc2c9c1a95.filesusr.com/ugd/dc6899_27921b2b3c164a58a80e4ad965507e28.pdf?index=true
    • https://uploads.strikinglycdn.com/files/1605fabb-2f1c-4d1e-b4b8-8ce55fcf32c4/element_roku_tv_remote_wont_work.pdf
    • https://8e0cabef-d481-4215-b437-8a5fc4e4723c.filesusr.com/ugd/f41140_734606092301488f8746ba55f4d2852c.pdf?index=true
    • https://945b3f91-9c76-4178-be32-f0dab3cfe2c6.filesusr.com/ugd/8d5d69_c2cff0800c6c4276bcf5aa30bcf85cdb.pdf?index=true
    • https://291e86d0-b4b7-455e-aeca-30cd05102b29.filesusr.com/ugd/384a46_1c9ef34673634a059ae47ea211da23ca.pdf?index=true
    • https://uploads.strikinglycdn.com/files/74f06067-c81f-4735-8add-0e61ad5c8936/weber_genesis_ii_e-210_cover.pdf
    • http://xaresuvilum.epizy.com/2011_ferrari_california_0-60.pdf
    • https://f7927488-8152-43cb-a667-e231f58cc5c5.filesusr.com/ugd/950cc9_6978dc1340d24fed81b16707a82f58f2.pdf?index=true
    • https://uploads.strikinglycdn.com/files/85acae5a-7168-4270-be41-a25772b87c81/mr._coffee_12_cup_automatic_drip_coffee_maker_manual.pdf
    • https://9dc8676a-0e58-44ee-a512-e339c7094702.filesusr.com/ugd/7c0652_e1379027ed0b4b13ae86555a07ed6ed9.pdf?index=true
    • https://uploads.strikinglycdn.com/files/3b743bea-d3f2-4fe0-a9fc-4d23f637d80a/60434608346.pdf
    • https://f8b2de7a-6012-4721-b8f1-df5267d6bb95.filesusr.com/ugd/8ebb60_2cc031cb73954f73a58c299279dee695.pdf?index=true
    • https://uploads.strikinglycdn.com/files/fe6782de-946b-41bc-b2ec-adcc9bf53e9a/call_of_duty_modern_warfare_pc_steam.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fed0.bin
1f5b372bdd3edce572fbe2e9555b082466567eed815b228e5fc991ce0a3d5ef0
pdf-font-stream PDF embedded font (sfnt) at offset 0xFED0 5600 bytes
font_01_sfnt_off000111d8.bin
67bcc631aaa8a2106660287e9f07b9acfb9abef985c05b7c361145db0791b83f
pdf-font-stream PDF embedded font (sfnt) at offset 0x111D8 11060 bytes