Malicious PDF — malware analysis report

Static analysis result for SHA-256 81060dbb8faa394c…

MALICIOUS

PDF

81.9 KB Created: 2021-02-28 10:26:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1a87d55608a422fdf49d036799c42a82 SHA-1: 59c0820f38221709b5e9c742a2673afd53a8a05d SHA-256: 81060dbb8faa394c34efd5a591c9d8ed8eb6b5cd4ddfca738689229efe8e9e07
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a link farm, suggesting a phishing or SEO manipulation tactic. ClamAV and ML classifiers strongly indicate maliciousness, with the PDF being flagged as Pdf.Phishing.Trojan. No scripts were extracted, but the presence of numerous external URLs points towards an attempt to redirect the user to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=shure+ulxd4q+antenna
    • https://gebapawuvafiv.weebly.com/uploads/1/3/4/5/134519736/ba052c574250ec1.pdf
    • https://static.s123-cdn-static.com/uploads/4496811/normal_6004180c597ba.pdf
    • https://nunofisodopuw.weebly.com/uploads/1/3/4/2/134234763/mefitaxosamasuvuduve.pdf
    • https://cdn-cms.f-static.net/uploads/4393785/normal_60381cc6d3886.pdf
    • https://static.s123-cdn-static.com/uploads/4457876/normal_60082848a7a35.pdf
    • https://bilimetib.weebly.com/uploads/1/3/4/4/134435282/binufulomoziresanod.pdf
    • https://cdn-cms.f-static.net/uploads/4489598/normal_5fd62e1b4401b.pdf
    • https://cdn-cms.f-static.net/uploads/4421352/normal_600ce6cd88727.pdf
    • https://cdn-cms.f-static.net/uploads/4494893/normal_601bb8c188a3a.pdf
    • https://fiwofufoneronup.weebly.com/uploads/1/3/1/0/131071066/sibujegir-bofekilulal.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/lemefofutomapox/16111281686.pdf
    • https://s3.amazonaws.com/leteraxewe/self_certification_form_for_ltc.pdf
    • https://s3.amazonaws.com/ruzaganog/12362244861.pdf
    • https://s3.amazonaws.com/tiluwisulepam/bhoothnath_movie_hd_video_songs.pdf
    • http://vexabimumemig.atwebpages.com/what_is_the_best_workout_to_gain_strengthen_knees.pdf
    • https://s3.amazonaws.com/panokojol/dnv_gl_lng_bunkering.pdf
    • https://s3.amazonaws.com/taturi/33990065554.pdf
    • https://s3.amazonaws.com/xugigabitulu/kidamixavubukafidib.pdf
    • https://s3.amazonaws.com/nojemi/digegajevavobo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010526.bin
4acb2b83cc88fcde715a1954df3236c628aa55d6f58574d70ea341feb117abc6
pdf-font-stream PDF embedded font (sfnt) at offset 0x10526 5120 bytes
font_01_sfnt_off0001168c.bin
125787b843a35111b5bb92f30faa9c5a1410baad9947be65457501d1076445ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x1168C 10768 bytes