Malicious PDF — malware analysis report

Static analysis result for SHA-256 85221715315d7016…

MALICIOUS

PDF

72.2 KB Created: 2021-03-25 08:40:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ae9817c3fa9c089c4eb5a71ce289f800 SHA-1: b8ddec1396db6666c821dcb4a6920a3f69f892e3 SHA-256: 85221715315d70161b0db341e275c6f54306256a4233db0b83e3b1382d3dc8a9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are part of a link farm designed for SEO manipulation. One prominent URL, https://lozipotod.ru/wix?keyword=learn+to+fly+unblocked+2, is directly embedded and likely serves as the primary lure. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/wix?keyword=learn+to+fly+unblocked+2
    • https://cdn-cms.f-static.net/uploads/4458621/normal_6045ff575bfab.pdf
    • https://cdn-cms.f-static.net/uploads/4373522/normal_60510bd905d09.pdf
    • https://cdn.sqhk.co/firataxoworo/jx1rs1k/22278941619.pdf
    • https://static.s123-cdn-static.com/uploads/4452626/normal_5ffe20542db05.pdf
    • https://cdn.sqhk.co/tifobebe/a1Vxia4/56062625768.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://bisapejavi.epizy.com/kosor.pdf
    • https://uploads.strikinglycdn.com/files/5c77bc17-5f9e-4dd0-8caf-bcbe8d990733/75505367589.pdf
    • http://jigiwema.epizy.com/pdf_market_leader_business_english_course_book.pdf
    • https://uploads.strikinglycdn.com/files/306defd3-4696-402d-a969-4b3d0efc7fe0/panchatantra_short_stories_in_hindi_with_moral.pdf
    • http://jodetiwozefiso.epizy.com/how_do_i_reset_a_kenmore_elite_dishwasher.pdf
    • https://uploads.strikinglycdn.com/files/8f2776c2-97ec-40d4-9a27-8d8d7a548353/yamaha_rx_a730.pdf
    • https://uploads.strikinglycdn.com/files/d4125d47-3515-49a4-a100-45c12ae32c48/bedejeru.pdf
    • https://uploads.strikinglycdn.com/files/f6a491e8-0991-46ed-840c-cc983bb26548/how_to_put_money_order_on_prepaid_card.pdf
    • https://uploads.strikinglycdn.com/files/e632de5d-7058-470d-a146-775ebddc6952/20889825412.pdf
    • http://kutegabirena.epizy.com/zeponusenitirikufatasaxa.pdf
    • https://4328a374-8b5c-4134-9cef-e132ca5fc89d.filesusr.com/ugd/6732b1_b48f8b18c6b24124a704e85eb0a4b05d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/9f39f5b3-85f8-4294-bb42-3c0716458cec/can_you_keep_a_secret_movie_2019_release_date.pdf
    • https://a0d2adcf-75bd-42a9-a42a-c23e1c6e9e1a.filesusr.com/ugd/85c99c_1f737613b5024bb5a0bdf81932ef63a7.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dcdc.bin
33aef41dd2c6747474120fcbae0ddc8043125cdf05ae82dea2148d5abc2c8e7d
pdf-font-stream PDF embedded font (sfnt) at offset 0xDCDC 5216 bytes
font_01_sfnt_off0000eeba.bin
40af25f59fb67188d69004bb08e698a70a02948d72eda6d067523f9ce68025f6
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEBA 10516 bytes