Malicious PDF — malware analysis report

Static analysis result for SHA-256 8425042bf092a2fe…

MALICIOUS

PDF

102.5 KB Created: 2021-03-17 17:29:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5de1088b42ce870e437792a4f2fe0a90 SHA-1: 7e1eba0e4dc00c56bde3f3fbd7f5b624a67719c3 SHA-256: 8425042bf092a2fe49ace3f20acdbcd914449e241ff424dd20ca0ade9fd0e683
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to potentially malicious domains, indicating a link farm or redirection scheme. ClamAV detected this file as a phishing trojan, and ML classifiers also flagged it as malicious. The document body is heavily obfuscated and appears to contain junk data, suggesting an attempt to hide the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9946

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=what+is+another+word+for+sunshine+recorder
    • https://cdn.sqhk.co/gutinisiv/hFEBUFY/super_smash_clash_brothers_full_apk.pdf
    • https://tinutenuku.weebly.com/uploads/1/3/4/6/134664278/552307.pdf
    • https://bujefodamefizup.weebly.com/uploads/1/3/1/0/131070612/e2c41c66.pdf
    • http://ruwosiju.getenjoyment.net/jibirixakalokin.pdf
    • http://zugapuvu.mywebcommunity.org/how_to_avoid_pattern_day_trader_rule_robinhood.pdf
    • http://xalapuzim.sportsontheweb.net/mulakox.pdf
    • https://cdn.sqhk.co/pevelefotuve/ehe8gdI/vabida.pdf
    • https://cdn.sqhk.co/gobuwovuv/tJ4hiha/pifalagibib.pdf
    • http://gipogup.sportsontheweb.net/zovugodaredudevekiti.pdf
    • https://litolojinoforiw.weebly.com/uploads/1/3/4/7/134721995/ketotutujofe.pdf
    • https://nuluziberalisox.weebly.com/uploads/1/3/1/3/131379655/4976384.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://uploads.strikinglycdn.com/files/e5e669c1-b741-48f4-9230-f092d2379eb7/bubble_sheet_template.pdf
    • https://uploads.strikinglycdn.com/files/7687d465-bc87-4b88-8810-2b463909b977/nuwaxexe.pdf
    • https://070488ba-e3d9-4c74-834b-445551f5513c.filesusr.com/ugd/fb83f1_32da67d798ab4919bb2bac085f9fab9d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d9b0afff-6305-4c8b-b625-14707080e408/jorge_luis_borges_books.pdf
    • https://ebcfae26-b4e4-4f1a-a5b2-c5bdbddc1bdf.filesusr.com/ugd/259f90_5bf44226095b44a780178deb6bfcc78f.pdf?index=true
    • https://d926c97b-7f3b-4ec8-a52a-318bcb589338.filesusr.com/ugd/120f26_0d65b174e4914e438945dc6e339b1d48.pdf?index=true
    • https://1a6defe7-92a0-4357-8a70-d3bce85d30c9.filesusr.com/ugd/385065_10f8daa4e40047df84f0e91e386cd021.pdf?index=true
    • https://98748e4b-3258-471a-903e-8ea98415cca0.filesusr.com/ugd/fd7405_a33ccb1e9b95414d80416cc4281d0c8d.pdf?index=true
    • https://68358877-4ee6-4e53-94f7-4bd9665c1f53.filesusr.com/ugd/3bbd68_30b1348283354e6b96b215f98a5d9de3.pdf?index=true
    • https://4f0f5a39-0a2f-4cdf-b4e4-40a644fad8b9.filesusr.com/ugd/2024fe_b113ed85d26b4b8bb3f2025dafc73fd4.pdf?index=true
    • https://03ca3561-abfe-48ca-9b59-b1b2b77f8126.filesusr.com/ugd/1af49e_c9efa0b282284031ae8d43f466974f47.pdf?index=true
    • https://c788b29d-df2d-4d46-9946-349e8cce89b7.filesusr.com/ugd/a9e086_3dc9f68358444fd1a77e3617501da6e7.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e544.bin
6f4f5b94d99a38aba322d34ef8b178107e9436b274453a3e111ac81508a72e28
pdf-font-stream PDF embedded font (sfnt) at offset 0xE544 7816 bytes
font_01_sfnt_off00010005.bin
060e12c07d2b07e5b95ebc50a2605d192115f5e24e558138db848f3da2713d6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x10005 5184 bytes
font_02_sfnt_off000111b5.bin
20cac70dbbc0987bf1b2d27cb8871c08f0db1255c9d3cbde138f020d3248aeb2
pdf-font-stream PDF embedded font (sfnt) at offset 0x111B5 4076 bytes
font_03_sfnt_off00012044.bin
adc1fdd571a8f6a45dd52b6b3e07ce0be5807f0d63c3f6b85355e03c7fd42e37
pdf-font-stream PDF embedded font (sfnt) at offset 0x12044 5700 bytes
font_04_sfnt_off00013297.bin
7f0ab0c4b703cdd3201e271124f42a3a286f166dc7027d95cd6b44859802c8a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x13297 14024 bytes
font_05_sfnt_off0001606c.bin
9eac11beef082b4c55e2aa4f9127b2cbb12e1b63d9e3c96a33465ff90f6fe155
pdf-font-stream PDF embedded font (sfnt) at offset 0x1606C 17484 bytes
font_06_sfnt_off00017a2f.bin
46842f6524cccc74ddf44b506c416b185a86cf2744e038c49bdf162ac003e8f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x17A2F 4232 bytes