Malicious PDF — malware analysis report

Static analysis result for SHA-256 891181be71079b43…

MALICIOUS

PDF

76.4 KB Created: 2021-03-18 05:15:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7d1b17dfe8613793418b9a1790aa4698 SHA-1: 76a788c73d0847f5849629a542fc381279a82a4d SHA-256: 891181be71079b433a670c03120a883974ce90eb559356c8e67145baddd513f1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a significant number pointing to S3 buckets and other domains, suggesting a link farm or distribution mechanism for malicious content. The heuristic PDF_SEO_LINK_FARM and the presence of an embedded URL indicate an attempt to redirect users to external resources. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/wix?keyword=led+tv+apk+cracked
    • https://cdn-cms.f-static.net/uploads/4471985/normal_601e52c83effe.pdf
    • https://static.s123-cdn-static.com/uploads/4454990/normal_5ffa23c24aca1.pdf
    • https://cdn-cms.f-static.net/uploads/4421939/normal_6050bb149bb53.pdf
    • https://cdn.sqhk.co/xosaletozobi/jjNkijU/black_demon_slayer_guide_osrs_2018.pdf
    • http://lamakexo.scienceontheweb.net/lumewo.pdf
    • https://cdn-cms.f-static.net/uploads/4498842/normal_605141ca854e7.pdf
    • http://mevukavotidu.getenjoyment.net/32563058431.pdf
    • https://cdn.sqhk.co/nivavepe/jeOBY6i/87202208091.pdf
    • https://static.s123-cdn-static.com/uploads/4413243/normal_5fdf17f2e58cc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/liguwubore/11162405122.pdf
    • https://s3.amazonaws.com/veledabejufi/luwonugajelavuwedovim.pdf
    • https://s3.amazonaws.com/rujimidujek/annotate_with_onenote.pdf
    • https://s3.amazonaws.com/fedure/is_newsmax_on_dish.pdf
    • http://vekabun.myartsonline.com/51573462004.pdf
    • https://s3.amazonaws.com/zarelusipofox/woxosobipazas.pdf
    • https://4ad55601-b8ab-4ae0-bc0e-e90069072326.filesusr.com/ugd/3aca14_0d533076958d4a29904dc2b0f16fd04f.pdf?index=true
    • https://7133fc40-0b9c-4701-b953-e7fafc934b44.filesusr.com/ugd/70a38d_6d551a8d9f0b4f2a867916f5ade41187.pdf?index=true
    • https://b67fa923-03b4-4d21-b555-95ff628d7525.filesusr.com/ugd/1d4b90_ac4ee13ae0624de49bc2127ce50ff5ca.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed57.bin
5a715bbc333546955181f6c511bbc7e7530ce1450c3d14e44abe8f757c24601b
pdf-font-stream PDF embedded font (sfnt) at offset 0xED57 4920 bytes
font_01_sfnt_off0000fe35.bin
149399f7e14f6c3ac0ee51fb9df8c692f4782e1dbc470a6b2c6206d191e84c96
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE35 11428 bytes