Malicious PDF — malware analysis report

Static analysis result for SHA-256 838522af695200b8…

MALICIOUS

PDF

81.3 KB Created: 2021-05-01 17:10:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c3a7080595b0f08866e8d9812b10eca4 SHA-1: 701018c8d606ba39636ed7819f442217293bf2c6 SHA-256: 838522af695200b879d45cc9257b86e843e5193311199847fca149f40ba4bef9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a technique often used for phishing or distributing further malware. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of outbound links, and ClamAV detected it as 'Pdf.Phishing.Trojan'. The embedded URLs suggest an attempt to redirect the user to malicious content, likely related to the lure of learning Microsoft Office Excel 2013.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/strik?utm_term=how+to+learn+microsoft+office+excel+2013
    • http://mudikovarew.mygamesonline.org/functional_requirement_specification.pdf
    • https://cdn-cms.f-static.net/uploads/4481271/normal_6010964345ba0.pdf
    • https://funogefoxareso.weebly.com/uploads/1/3/4/0/134041001/2497071.pdf
    • http://contact-git.top/2004_honda_vt1100c2_shadow_sabre_specsd80bq.pdf
    • https://vejanozamafiz.weebly.com/uploads/1/3/5/3/135351199/radajil.pdf
    • https://mepagalupotope.weebly.com/uploads/1/3/4/2/134265457/9738383.pdf
    • http://mavito.online/teruzuminemuboxokawfwlv8.pdf
    • http://magnitoli-2ekran.site/zudasjgj4c.pdf
    • https://tomoniwibisuxis.weebly.com/uploads/1/3/5/9/135961627/3535903.pdf
    • https://static.s123-cdn-static.com/uploads/4418984/normal_5ff713bac035e.pdf
    • https://static.s123-cdn-static.com/uploads/4413976/normal_6000d03916367.pdf
    • https://static.s123-cdn-static.com/uploads/4457573/normal_5feb26b2036f6.pdf
    • https://cdn-cms.f-static.net/uploads/4393189/normal_606846aa863b6.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/pegozegi/36588276991.pdf
    • https://855e1e5b-0daf-4dce-aa73-dfad2bfec5df.filesusr.com/ugd/ced2dc_70f00049058c46b69f747a8ec3aaf550.pdf?index=true
    • http://satovimowenijor.myartsonline.com/tactics_for_toeic_listening_and_reading_test.pdf
    • https://47ab6ce1-aee6-4086-a8e7-31fe393d2411.filesusr.com/ugd/afbef4_f298c052adba4a8aa7c7db524a490738.pdf?index=true
    • https://s3.amazonaws.com/jukoxisojow/wedding_invitation_online_free_templates.pdf
    • http://livirava.atwebpages.com/23717085026.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ff12.bin
86370350ee90ce070e82942f8c83f9ade7c91f545d714c5c825042e8fdfd8056
pdf-font-stream PDF embedded font (sfnt) at offset 0xFF12 5636 bytes
font_01_sfnt_off00011241.bin
afd5e6705c39ee6f37d2c48d2757464fdaa0bb2e3bef929b3be7a41ae40052f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x11241 11064 bytes