Malicious PDF — malware analysis report

Static analysis result for SHA-256 93b18e8daecfba7a…

MALICIOUS

PDF

88.2 KB Created: 2021-03-24 12:01:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8c9a721c83988989f8c2c06e409ef418 SHA-1: e0a8480e77105bf82f89adf430f39d3a605b342a SHA-256: 93b18e8daecfba7a3214fe5cddaeced55edae0d3d5501dabaa5f9b3b701c4515
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file contains a large number of external links, many of which point to other PDF files hosted on various domains. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, suggesting an attempt to manipulate search engine results or distribute malicious content. The ClamAV detection and ML classifier strongly indicate maliciousness, likely related to phishing or malware delivery. While no scripts were directly extracted, the structure and numerous external links point towards a malicious intent to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=discrete+maths+functions+pdf
    • http://gnfcns.info/potezilojowaronowosapipal2hh1.pdf
    • http://3203epworthcres.com/air_conditioning_maintenance_agreementup1ti.pdf
    • http://devlp.design/infosys_off_campus_placement_papers_freeul4ro.pdf
    • http://lumacy.site/falcon_bms_israel_theater_downloadl2iie.pdf
    • http://salet.store/roomba_770_error_5k04d9.pdf
    • http://joy-todays.online/nupumojubvdv8o.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://ea64ff4c-51e6-4efc-8cc1-399682447901.filesusr.com/ugd/961f18_9b55629b85b74d2694be85432cc89acb.pdf?index=true
    • https://s3.amazonaws.com/geradi/59071643872.pdf
    • https://71a5d838-4e22-4830-8da1-7955ec3365f5.filesusr.com/ugd/f2f43e_50d192749de347bab85c15f3a23e6d24.pdf?index=true
    • https://0315d410-4255-45a3-9477-873949dd02ac.filesusr.com/ugd/f85006_2220de48c17e4c7eb6c71864dc20a709.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a1f92e89-4d9c-41dc-b7da-adae00840323/vuseretidunajiniba.pdf
    • https://s3.amazonaws.com/mufukep/best_thing_to_mix_with_crown_royal_black.pdf
    • https://0ffdd24b-620b-4f4d-94ef-a39da1ca20bd.filesusr.com/ugd/853ce2_1b59a816c39249a3bac3e4eda7b5a785.pdf?index=true
    • https://s3.amazonaws.com/kiguteperilodu/cmhc_rental_market_report_vancouver.pdf
    • https://s3.amazonaws.com/dagasopones/dracula_stokers_response_to_the_new_woman.pdf
    • https://s3.amazonaws.com/fedure/lg_air_conditioner_error_code_ch_52.pdf
    • https://s3.amazonaws.com/gopifu/nuwamifavinedojufibige.pdf
    • https://0dd4521b-3e41-4083-9bcc-807cce03ae78.filesusr.com/ugd/cfe2e9_fc22292bed074bcb858cc8e3d0cd2140.pdf?index=true
    • https://uploads.strikinglycdn.com/files/e510c36e-322a-40e5-8a57-47d56775813b/what_is_dorian_grays_painting.pdf
    • https://s3.amazonaws.com/viboxikuz/9990871130.pdf
    • https://s3.amazonaws.com/tirimofufemukat/chatal_band_dj_2018_naa_songs.pdf
    • https://uploads.strikinglycdn.com/files/82fead11-fd32-4514-be85-ee035f730674/76521405458.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001178c.bin
edfeb991c357d7761caded274a1d75c02a1748b2d223a7e67f6c9c9980567400
pdf-font-stream PDF embedded font (sfnt) at offset 0x1178C 5360 bytes
font_01_sfnt_off000129a0.bin
f6efc6e9c4ce8d68ba786f13165bc96707c42e7c362b5b73af5cd2cf4663e983
pdf-font-stream PDF embedded font (sfnt) at offset 0x129A0 12052 bytes