Malicious PDF — malware analysis report

Static analysis result for SHA-256 81064354eb24f30a…

MALICIOUS

PDF

90.0 KB Created: 2021-05-07 10:41:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 757c78132e14ac6e5cfe4b6edc164e18 SHA-1: ae1d9d0cbbbb07cc91d92a1704e1c74892f3a770 SHA-256: 81064354eb24f30aa7c3b6eea70f78a048cfd33ec8c9fd1ea2d489a934216db3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to potentially malicious domains, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV also flagged this file as malicious, specifically as a phishing trojan. While no scripts were directly extracted, the presence of numerous external links suggests an attempt to redirect users to malicious content or phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=tipos+de+derechos+fundamentales
    • https://cdn-cms.f-static.net/uploads/4410678/normal_602c51d5b2a9f.pdf
    • http://mezogevap.mypressonline.com/arborescence_site_web_exemple.pdf
    • https://cdn.sqhk.co/rakapuvad/ooXCcjh/logo_quiz_answers_level_6_wholesale.pdf
    • https://cdn.sqhk.co/bogovureg/giajgjd/starlink_battle_for_atlas_ship_stats.pdf
    • https://cdn-cms.f-static.net/uploads/4369783/normal_604b3b0752c29.pdf
    • https://static.s123-cdn-static.com/uploads/4403808/normal_5fdea29e30a72.pdf
    • https://cdn.sqhk.co/fowoleleda/gfifif2/23214781486.pdf
    • https://cdn-cms.f-static.net/uploads/4376379/normal_60146795f148e.pdf
    • http://fusekimutoxi.sportsontheweb.net/47387233330.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/e9aa98e4-ceaf-4d61-9764-dd3d2b6b7faa/modern_physics_class_12_in_hindi.pdf
    • https://5366dd3f-28a3-4342-b8e5-5bed86455aec.filesusr.com/ugd/a92322_f48bae59932a4836b8eba83fc1de3aaf.pdf?index=true
    • https://uploads.strikinglycdn.com/files/7a4d1821-5c83-4186-ba92-5932f681186f/nagixe.pdf
    • https://uploads.strikinglycdn.com/files/2fcfd4df-cbab-4c09-82a6-d1550ceb9382/34587104456.pdf
    • http://bujijawuta.atwebpages.com/psychological_testing_and_assessment_book.pdf
    • https://uploads.strikinglycdn.com/files/c534f9b8-7804-4fab-9b78-10515883f59b/bulorugonituwibu.pdf
    • https://uploads.strikinglycdn.com/files/fa51c6c2-1358-42f7-a393-8433d2fff3d3/troy_bilt_lawn_mower_belt_replacement_deck_drive_belt_a94.pdf
    • https://5ce19dfa-329f-495d-88d1-e1e7834d9072.filesusr.com/ugd/d902bb_6422e54933d8493eab07c4174a7761a1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/551dfd0d-1b25-414e-8e2b-abfb5f59ad75/vodebatisekik.pdf
    • https://uploads.strikinglycdn.com/files/a91c15e1-b302-4dcf-a28b-710412b8efca/61316505282.pdf
    • https://uploads.strikinglycdn.com/files/096d07e8-8bde-446a-b1d1-03f967d242c9/fizowurujusexonozi.pdf
    • https://5c90cfa9-af55-48e2-9430-1f3580382729.filesusr.com/ugd/e2b09b_329992b7ce7b42ccb738de6e772d4c1d.pdf?index=true
    • https://d1159ab4-cbf5-42eb-897b-83a5e94cd7da.filesusr.com/ugd/536122_4f6f525526c74f38a008e76704fcd8a9.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e2878f27-7c9e-4097-8fcc-6c47f7e6f33d/89682013120.pdf
    • https://828c6a01-da61-4814-986a-f72e64f4f334.filesusr.com/ugd/cdfdba_276987779fd843c1a1ece0f12f3b550b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00013b00.bin
c01872fdedaf0125bdc07585f9a6ccfacdb9f888cfcb40d0cc5ea1e5e87c3789
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x13B00 18576 bytes
font_00_sfnt_off0000fa3c.bin
1b1955f6bdb890a6088b79a8646f78c78f331293bb7fb5c0f30655f57c04a3ce
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA3C 5344 bytes
font_01_sfnt_off00010c31.bin
3a37df3de72ec4473d970579e20ce90873368aedf9b38621b3d2ccbda9597b99
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C31 1584 bytes
font_02_sfnt_off0001144d.bin
fb88a7609305ae3825a4089850913fdabe2f9070816af4fff25d9ef61ffabea4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1144D 11852 bytes