Malicious PDF — malware analysis report

Static analysis result for SHA-256 939430926c1b3cc1…

MALICIOUS

PDF

99.8 KB Created: 2021-03-23 16:49:08 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ef43ea4e2616e90413fab35f8cf63b1f SHA-1: 786fdf6a61da741cc8bd45549ce2a3909c896626 SHA-256: 939430926c1b3cc133eb33db73d5092a692a505dab79d069484df6194fb9dd8d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' and 'PDF_URI' heuristics. The ML classifier and ClamAV detection strongly suggest malicious intent. The embedded URL likely serves as a lure to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/wix?keyword=the+little+book+of+valuation+%25E0%25B9%2581%25E0%25B8%259B%25E0%25B8%25A5%25E0%25B9%2584%25E0%25B8%2597%25E0%25B8%25A2+pdf
    • https://cdn.sqhk.co/dabozijide/6hghccO/tunnel_rush_2_players.pdf
    • https://cdn.sqhk.co/xogatijixe/tggIicb/x_core_hunter_not_working.pdf
    • https://cdn.sqhk.co/razefudixid/iegj1nL/domezebeletupimi.pdf
    • https://cdn.sqhk.co/tubafejog/LPicpgd/lunesubukoj.pdf
    • https://cdn.sqhk.co/vivepovugeli/ia87hhz/82822725041.pdf
    • https://cdn.sqhk.co/fakineduxafe/dy4ia2h/willie_nelson_cowboy_songs_youtube.pdf
    • https://cdn.sqhk.co/nuroteditu/dhggdhb/nintendo_switch_review.pdf
    • https://cdn.sqhk.co/fewukise/n6DdUDw/77053219162.pdf
    • https://cdn.sqhk.co/ribafesupuro/dhiv29q/draw._io_offline_ipad.pdf
    • https://cdn.sqhk.co/kutajanode/xjdmif5/prodigy_math_game_level_100_hack.pdf
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vazisi/muwidadadoxurijivus.pdf
    • https://s3.amazonaws.com/wopari/what_does_it_mean_when_a_lizard_licks_you.pdf
    • https://f0198b83-f3fe-41b4-8315-bacd7eabb238.filesusr.com/ugd/2b3f46_a7cb300cb65d46a5b44efaa5a73dfae5.pdf?index=true
    • https://s3.amazonaws.com/limepusotanal/zutipokobujivaso.pdf
    • https://s3.amazonaws.com/xufaxoferugod/vba_excel_date_format_change.pdf
    • https://s3.amazonaws.com/lorifawuvawot/38298920418.pdf
    • https://s3.amazonaws.com/jifedefujodu/xuxun.pdf
    • https://s3.amazonaws.com/satudifin/tokadasoz.pdf
    • https://c8070bf9-ed42-4c5d-8eb8-ca35ee70f136.filesusr.com/ugd/d38238_8c4d9af826e14c9b9ef6dec99342d914.pdf?index=true
    • https://s3.amazonaws.com/gawabog/dijonuzelotofezawula.pdf
    • https://s3.amazonaws.com/zonebon/autocad_isometric_drawing_exercises.pdf
    • https://8d59741e-369e-44be-b01e-8fbcb09d2d01.filesusr.com/ugd/7cefa9_f19155ac36c04089881082fd75d05ce7.pdf?index=true
    • https://s3.amazonaws.com/tobovunoberiki/gipisiwuk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off000129f2.bin
c6c493bbca83dd576609c51d20d89001b7ee6eb36241114ab31cf16c7ea828f1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x129F2 17332 bytes
font_00_sfnt_off0001070f.bin
b2444bbe1d33ba316be936f4e333c1215ca3283fa2a7948f57872cc77e3588a8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1070F 5068 bytes
font_01_sfnt_off0001184c.bin
e7792b9483939b65627b5095f2531aba7d1cb71543c8ccad373af821ee59b72b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1184C 6904 bytes
font_03_sfnt_off0001589a.bin
a3c12980088903fb2238c11f335188eb566d2057b6b921bd752f94a5be3258ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x1589A 10500 bytes