Malicious PDF — malware analysis report

Static analysis result for SHA-256 8eec44242e8cd3b5…

MALICIOUS

PDF

80.2 KB Created: 2021-03-13 23:48:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7c8408f1a5189dc8976006e5cc2a6721 SHA-1: 8db90faa4b005f8c123d1c2cefd5a0621c02cc72 SHA-256: 8eec44242e8cd3b5e99fbc880654d2b283290f3628ae4b9981aeef985b6cc010
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, many of which point to other PDF files, suggesting a link farm or SEO poisoning tactic. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. While no scripts were explicitly extracted, the presence of numerous external URLs and the heuristic firings point towards a malicious document designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=nespresso+d50+manual
    • http://lg-copyrightforms.com/wezutirokojjp82.pdf
    • http://vodoroding.info/stephen_king_it_2017_book_cover750pn.pdf
    • https://guvusogom.weebly.com/uploads/1/3/5/3/135324715/gobakefu.pdf
    • http://koxelovanalimu.getenjoyment.net/wavesojixe.pdf
    • https://jinobodusere.weebly.com/uploads/1/3/4/7/134722577/vatoduxoxifofegukaw.pdf
    • http://insurancecarusa.com/bhaja_govindam_telugu_meaning6gii6.pdf
    • http://ooovseanalizi.ru/punefikuwikazj9m8o.pdf
    • http://hookup154.site/mewoguvumapovewoxisemaluvyxnc8.pdf
    • http://znatural.space/56084885506yfhr.pdf
    • https://pujuwofox.weebly.com/uploads/1/3/4/8/134882524/682e0b4.pdf
    • http://logoped-samara.ru/bypass_frp_with_pc_android3f347.pdf
    • https://rigefenasoje.weebly.com/uploads/1/3/0/7/130776330/savajesowijiwaxuxuda.pdf
    • http://ig-copyrighthelpcenter.com/tobepuk0dpx.pdf
    • https://malilojomatade.weebly.com/uploads/1/3/4/3/134354128/buluvinuzosetejegap.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://42e65457-ec34-4553-8979-78b6e302f774.filesusr.com/ugd/f1976d_4e39a9aaa4734214b4b59bb8597bccd0.pdf?index=true
    • https://eac5c218-d238-408c-98a6-8ff0ecbb25fc.filesusr.com/ugd/b1277d_3662a3db5dfb4d278a7654ce2c420954.pdf?index=true
    • http://mujebik.atwebpages.com/38119038370.pdf
    • https://636e06b3-920c-4898-b827-ef778bbbc101.filesusr.com/ugd/40512e_1230630ed331476fb3e74c43f05c491e.pdf?index=true
    • https://696f1bd8-06c3-47a7-a8f7-e83e17ec8d18.filesusr.com/ugd/5ad03d_dcd1898376c0451ca2744c5de6c1b9a5.pdf?index=true
    • http://kagijido.myartsonline.com/zorizufeporuwup.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb6c.bin
a9ec539a19f056f14452f0f1d7a175d624a636aa9ad2c0894009a47adcca48d2
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB6C 5096 bytes
font_01_sfnt_off0000fc9e.bin
3cc6567042ff6699be63bc7b7de5d091e57d47aa13b3abef85a9b8d17485f986
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC9E 14040 bytes
font_02_sfnt_off000125ce.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x125CE 4324 bytes