Malicious PDF — malware analysis report

Static analysis result for SHA-256 90e395a5e6ccfa2e…

MALICIOUS

PDF

70.8 KB Created: 2021-03-14 13:13:40 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-22
MD5: d8e977a5539c0f1ebf58332425a20223 SHA-1: d6563702c3a5d238b582c78b654893f799c82d9b SHA-256: 90e395a5e6ccfa2e749fa96a6f43f06b74273168bd9d3497d420b286be1c1f50
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which point to PDF files hosted on various domains and cloud storage services. This behavior is indicative of a link farm or SEO poisoning attack, designed to drive traffic to malicious sites. The ClamAV detection and ML classifier flagging further support its malicious nature. While no scripts were explicitly extracted, the PDF structure and numerous external links suggest an attempt to redirect users to potentially malicious content or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=yamaha+rx-v673+internet+connection PDF link annotation
    • https://zurirepazigotot.weebly.com/uploads/1/3/0/9/130969164/bijugovogara.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374968/normal_603fff8f6d186.pdfIn PDF document text
    • https://polisurev.weebly.com/uploads/1/3/0/7/130740145/jipipotux-damofetasanawu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368477/normal_6031abf8553b5.pdfIn PDF document text
    • https://ganunosor.weebly.com/uploads/1/3/0/8/130814229/gopoz-nujuroxegog-gipatufilawa-welagozi.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4402706/normal_604c99881b8c4.pdfIn PDF document text
    • http://jarevine.mywebcommunity.org/digamutexijekagenewijidon.pdfIn PDF document text
    • https://jixejuterekafiw.weebly.com/uploads/1/3/4/5/134508928/xaxega-mijixibe-piniberajuzaka-nutejoj.pdfIn PDF document text
    • http://lenugaguv.medianewsonline.com/ego_power_56_volt_cordless_lawn_mower_reviews.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4427274/normal_6017f7048b7d9.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fupanabivote/85780255632.pdfIn PDF document text
    • http://nudoritane.atwebpages.com/14450856372.pdfIn PDF document text
    • https://s3.amazonaws.com/zuwimadaneb/28499093112.pdfIn PDF document text
    • https://s3.amazonaws.com/genedesowul/project_management_meeting_follow_up_template.pdfIn PDF document text
    • https://s3.amazonaws.com/dazinibonofobi/lowercase_alphabet_handwriting_worksheets.pdfIn PDF document text
    • http://tevefetilojas.atwebpages.com/wepemototegiwipotuga.pdfIn PDF document text
    • http://pivimufe.atwebpages.com/video_games_ps4_vr.pdfIn PDF document text
    • https://s3.amazonaws.com/voxulija/vabaxir.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/16602605-e85a-47cc-898c-2e08af806ca7/gujosifamufefi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/89335d21-eb4d-46a8-af4f-976390d239a7/7075574502.pdfIn PDF document text
    • https://s3.amazonaws.com/jemazejodep/diablo_3_botting_guide.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d513.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD513 5348 bytes
SHA-256: ec5ebcdb7df9ad4a767a503e3bbc8eab088c6b85a65d859e77745d2179b28cd1
font_01_sfnt_off0000e732.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE732 10984 bytes
SHA-256: 8e2153260c16181fe19fad881b9d034b8e8a96d6a60f443a4d46c8dbab4b5926