Malicious PDF — malware analysis report

Static analysis result for SHA-256 862a245b3337951e…

MALICIOUS

PDF

68.4 KB Created: 2021-03-30 20:56:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1b64e6ce31899922ce04db5686ff9253 SHA-1: a613f6c99a0b26bfca5d74923d2c106a44f3be4b SHA-256: 862a245b3337951e4824eb56196421383b3bf869c2d12038f5a7482104693a97
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains numerous external links, a common tactic for phishing or malware distribution. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting an attempt to create a link farm or distribute malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent. Although no scripts were extracted, the presence of many external URLs points to a likely attack pattern of luring users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=honda+mower+hr214+service+manual
    • https://cdn.sqhk.co/zikegasenar/jejbvoe/rokikarilagifefaperifisig.pdf
    • https://ruliduwaj.weebly.com/uploads/1/3/4/0/134016670/tokipefuzede.pdf
    • http://robertferrell.net/dowuxagexutomawosevepubiuivhy.pdf
    • http://winoraama.space/machine_element_design_notes82w00.pdf
    • http://wisecreditscore.info/how_many_days_a_week_do_you_need_to_work_out_to_see_resultsft6cb.pdf
    • https://cdn.sqhk.co/fogobewataja/jffhjhf/kimave.pdf
    • http://creditstar-kabinet.com/789653013727uttd.pdf
    • http://discount50it.pro/airtel_recharge_code_nigeriab2eop.pdf
    • https://cdn.sqhk.co/tufuboloruj/ggYNgjD/stone_age_boy_book_review.pdf
    • https://sotevujek.weebly.com/uploads/1/3/4/0/134012487/pevepukuxame-lemaw.pdf
    • http://martakkord.ru/what_is_hardware_and_software_short_answereuruo.pdf
    • https://lotatodekimin.weebly.com/uploads/1/3/4/7/134705716/6116046.pdf
    • https://cdn.sqhk.co/wanoziku/EUFggYH/horror_wallpaper_hd_1080p_free_download_for_mobile.pdf
    • https://negapisege.weebly.com/uploads/1/3/4/6/134635707/jebevezusixoj-jorafenigidomi.pdf
    • https://cdn.sqhk.co/lofesaxudiwo/1jjSgdO/lubupezo.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/joterige/how_to_renew_nj_drivers_license_during_covid_19.pdf
    • https://s3.amazonaws.com/panalipolifod/78466606020.pdf
    • https://s3.amazonaws.com/jifedefujodu/xiganelosevejiwozimo.pdf
    • https://s3.amazonaws.com/tokit/98131270745.pdf
    • https://s3.amazonaws.com/tezude/parexaref.pdf
    • https://s3.amazonaws.com/zumomasugipeno/issb_test_date_sheet_2018.pdf
    • https://s3.amazonaws.com/tazopaju/5460632768.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cec4.bin
2eb4d4e4b12def6e3f599c286765f6e9965966c8acb95d5561f42e75be574058
pdf-font-stream PDF embedded font (sfnt) at offset 0xCEC4 5564 bytes
font_01_sfnt_off0000e1a6.bin
f5f71aefa2f9db7d3379d6ee74e40421bdb4338cf0d19084dd58091f7de973ba
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1A6 10200 bytes