Malicious PDF — malware analysis report

Static analysis result for SHA-256 93223cb6ffe53dfa…

MALICIOUS

PDF

81.3 KB Created: 2021-04-14 01:22:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7d82df2250e0ad161912eea017b79a72 SHA-1: b614f48990ea30f7b7925f3db2adb0f425350dc9 SHA-256: 93223cb6ffe53dfa9c96f7ce9640ffa8eebfb799351a6d5fcfe5056afcb2d320
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning model returned a high probability of maliciousness. The heuristic PDF_SEO_LINK_FARM indicates the presence of a large number of external links, with the primary ones being to suspicious domains. While no scripts were explicitly extracted, the nature of the PDF and the embedded links suggest it's designed to redirect users to malicious sites, potentially for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9961

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/strik?utm_term=is+wilderness+survival+a+required+merit+badge
    • http://goodsfor.life/disorderly_conduct_charge_in_georgiab6mr9.pdf
    • https://cdn-cms.f-static.net/uploads/4416656/normal_604ccc11be238.pdf
    • https://static.s123-cdn-static.com/uploads/4375196/normal_5fe54811c6944.pdf
    • https://cdn-cms.f-static.net/uploads/4414164/normal_601ca280cbb7a.pdf
    • https://static.s123-cdn-static.com/uploads/4459477/normal_5ff38f2e816f9.pdf
    • https://cdn-cms.f-static.net/uploads/4384150/normal_602a3f7485611.pdf
    • http://pigalimiru.medianewsonline.com/33538893254.pdf
    • http://posadukik.getenjoyment.net/puziwivafemomutikuvir.pdf
    • http://reabook.online/bipozerajiwelewe1g0i9.pdf
    • http://goodnaturak.space/bollywood_song_ringtone_download_2019_mp3q2ay8.pdf
    • http://kvadro63.ru/how_to_write_an_essay_for_college_examplesf0zcq.pdf
    • http://zakosemej.mypressonline.com/tiwawomepesodobamodemupe.pdf
    • https://static.s123-cdn-static.com/uploads/4403540/normal_60071cdd2afef.pdf
    • https://cdn-cms.f-static.net/uploads/4369783/normal_601da6daac5aa.pdf
    • http://ladebizelase.scienceontheweb.net/21184934621.pdf
    • https://cdn-cms.f-static.net/uploads/4418778/normal_600c739d6ef63.pdf
    • http://jusukigib.sportsontheweb.net/i_pace_max_charge_speed.pdf
    • https://cdn-cms.f-static.net/uploads/4476123/normal_606cd79d9c25a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://348ddb29-83e1-4812-94a1-743b72ef9b42.filesusr.com/ugd/23b571_53018ebcf2524bcb96ea00069b817633.pdf?index=true
    • http://popofisofol.myartsonline.com/crossfit_wod_maker.pdf
    • https://02408c19-b9f6-4996-a596-1d5b7e46c8d3.filesusr.com/ugd/c83fdb_5f971c1a3f4f4fa498ede766449cf29c.pdf?index=true
    • https://0ffdd24b-620b-4f4d-94ef-a39da1ca20bd.filesusr.com/ugd/853ce2_9b564f8a1889414ea7cd88f4be35d010.pdf?index=true
    • http://bidusibebawuz.onlinewebshop.net/24241107182.pdf
    • https://7f1d4f38-7308-4051-b389-b8ed31312188.filesusr.com/ugd/e948c1_f261dd5794d24ea4a838dc6007335af3.pdf?index=true
    • http://vilepobafomunow.atwebpages.com/how_to_fix_braun_thermometer_pos_error.pdf
    • http://pidodexogejax.myartsonline.com/administrative_management_theory_by_henri_fayol.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010100.bin
9d3405ee29670d97322db9b1697c6c16a92daeae125c816f5aea0c4f0e9397a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x10100 5500 bytes
font_01_sfnt_off000113ab.bin
2af1aaa3614c7dce085880cfb230e42756eca23af4e5a1e781e80d6be558d5c7
pdf-font-stream PDF embedded font (sfnt) at offset 0x113AB 10188 bytes