Malicious PDF — malware analysis report

Static analysis result for SHA-256 8121c26822ec0ae2…

MALICIOUS

PDF

79.2 KB Created: 2021-03-05 12:24:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 69ad33a777a88d0619863176544c9ff8 SHA-1: 560b3d88d229744fc112e148873d678c43cfc0bd SHA-256: 8121c26822ec0ae29a81d1dbb3f229303d8f2305fd1f10070c14b5dbbab6ca54
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying a 'PDF_SEO_LINK_FARM' pointing to multiple PDF files hosted on suspicious domains like 'gatorama.fun'. The document body, though heavily obfuscated, contains text related to 'Lakshmi ashtakam lyrics', suggesting a lure to disguise the malicious intent. The presence of external URIs and the ML classifier's high confidence score indicate malicious activity, likely aimed at redirecting users to malicious content or downloading further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://crophysi.ru/123?utm_term=lakshmi+ashtakam+lyrics+in+english+with+meaning
    • http://gatorama.fun/losuk2qs0e.pdf
    • http://com-signto6.xyz/dipuramipodidajugikosredvd.pdf
    • https://kaxudafesin.weebly.com/uploads/1/3/4/3/134355678/detipazomoleta.pdf
    • http://magnitoli-2ekran.site/texas_instruments_ti-84_plus_not_turning_onter0k.pdf
    • https://tupisefam.weebly.com/uploads/1/3/1/3/131383837/8587843.pdf
    • https://bapudemajupi.weebly.com/uploads/1/3/1/4/131438294/333ef3dbef99d0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://uploads.strikinglycdn.com/files/eacb654a-a34d-4ac2-acc6-1e7adeb76f78/cricut_expression_2_connect_to_internet.pdf
    • https://1c684d3d-b1aa-4d58-8f8e-408f9cf37fac.filesusr.com/ugd/64d889_d0310825fb674568be7d7532c57fee58.pdf?index=true
    • https://uploads.strikinglycdn.com/files/37defa4d-280a-43f9-a24b-63b2b6c0cbe6/kimutabe.pdf
    • https://uploads.strikinglycdn.com/files/688ef080-ada5-474b-b949-c50df8729833/57349300211.pdf
    • https://69a21580-3c80-4f81-8097-1ec0bc18215d.filesusr.com/ugd/bd7df1_5bdff726234042e982c9cc4fc217be8d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d29693aa-fc11-4ce6-9914-16843426b2f8/68651818218.pdf
    • https://s3.amazonaws.com/patotale/74115982430.pdf
    • https://uploads.strikinglycdn.com/files/d30656ae-f2c2-4421-a0e6-730c6846800d/what_are_the_mudras_in_yoga.pdf
    • https://s3.amazonaws.com/perurulexi/daxaluraresapij.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dee4.bin
bcb7d1c46f1736701352c4a0bb36c4b55c0fb2c02b40e3490cb094f0007970e5
pdf-font-stream PDF embedded font (sfnt) at offset 0xDEE4 5412 bytes
font_01_sfnt_off0000f13a.bin
4707bf859c2b2b552e51fb2091ad8c8f9f3049b019adc279754ac00abd2d80ce
pdf-font-stream PDF embedded font (sfnt) at offset 0xF13A 2140 bytes
font_02_sfnt_off0000faab.bin
de4bb0152be9e9bb118c80499050ee62e021374f1164eebab4c7006309812440
pdf-font-stream PDF embedded font (sfnt) at offset 0xFAAB 3772 bytes
font_03_sfnt_off0001064f.bin
c7aca4ba7a96c856c48ac008d2d58acaf803636c96bc3d7b48838d96384e7db6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1064F 12444 bytes