Malicious PDF — malware analysis report

Static analysis result for SHA-256 878cf688aee04567…

MALICIOUS

PDF

94.3 KB Created: 2021-03-25 06:33:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 33605a0e1f9f68d0a96ae96ecb418c8e SHA-1: 72b8cdc04c251ff0d2be90f4bd34ecf84d15739c SHA-256: 878cf688aee045673b372a5552dd1ff318146e1fe54e6d728074f71e98a6767e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to PDF files, indicative of a link farm or SEO spamming technique. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. The embedded URLs are the primary indicators of compromise, directing users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/123?utm_term=durian+fruit+nutritional+information
    • https://cdn.sqhk.co/ranotigu/djg7Jhe/sivipodawedufovedaget.pdf
    • https://static.s123-cdn-static.com/uploads/4457006/normal_5fe36840dca33.pdf
    • https://cdn.sqhk.co/lolajelor/hfiqPfW/puppy_love_my_dream_pet_game_online.pdf
    • https://cdn-cms.f-static.net/uploads/4379487/normal_603408a2cf736.pdf
    • https://cdn-cms.f-static.net/uploads/4369524/normal_6015bd5276130.pdf
    • https://cdn-cms.f-static.net/uploads/4445326/normal_6041b5e51c779.pdf
    • https://cdn.sqhk.co/zuvaworizon/6igjhhd/46191182375.pdf
    • https://static.s123-cdn-static.com/uploads/4460243/normal_60094e1edcc68.pdf
    • https://cdn.sqhk.co/fodexuxefeba/aWBgcJU/metal_slug_2_xbox_360.pdf
    • https://cdn.sqhk.co/zumiredosuwi/hbgggji/speed_of_sound_coldplay_sheet_music.pdf
    • https://cdn-cms.f-static.net/uploads/4371505/normal_602946a89a86d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://d85b1738-a471-4043-b59e-116b2bb794a3.filesusr.com/ugd/97927e_e991d85a4d1844fba672ddda0be0fe73.pdf?index=true
    • https://2bb9e989-9ce9-409f-aa8a-839f2ea8d3bf.filesusr.com/ugd/9f8cc2_964ac2c43b8e4b48826a6155da424f7e.pdf?index=true
    • https://0ea1ff7f-05b3-43a2-9744-178351a05ed1.filesusr.com/ugd/01f9b9_7725006110a0478fb600968f1473012a.pdf?index=true
    • https://891dfe3a-8969-4df2-b253-5ccc4ebbb7a0.filesusr.com/ugd/e66789_3c890edfc0b742cfb0726c2159bb65f6.pdf?index=true
    • https://4a5660cc-52a2-48ff-9acb-4b4f1704cb6e.filesusr.com/ugd/81868d_b9ff020fc912460cb597b5d718d1dff3.pdf?index=true
    • http://rejaromavovelu.rf.gd/paper_leaf_template_free.pdf
    • http://tifatorebuvu.epizy.com/duwazugiwaberekobolupub.pdf
    • https://5e024257-ca51-40df-b6b5-a3104c7b7124.filesusr.com/ugd/97368a_c6666723853342a4bd76676aae9ca18f.pdf?index=true
    • https://48bf584d-d56c-45cf-b4f3-c1c05dce5274.filesusr.com/ugd/3f4b99_51956945ecad4f5ba21a1624c33892b7.pdf?index=true
    • http://nopizimexid.rf.gd/garmin_nuvi_52_motorcycle_mount.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001358c.bin
3a87262ef56cd0cf1c9a7e416db793a5e21fce6a862b7fa8b52106d8fd136526
pdf-font-stream PDF embedded font (sfnt) at offset 0x1358C 4732 bytes
font_01_sfnt_off00014596.bin
1ecca239b1cb6a6d4959c6e89a898bd72608f20b8095af407a100ddc4ef5400a
pdf-font-stream PDF embedded font (sfnt) at offset 0x14596 11188 bytes