Malicious PDF — malware analysis report

Static analysis result for SHA-256 9552fe4941f0e98c…

MALICIOUS

PDF

72.7 KB Created: 2021-03-15 09:27:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2aaea62991fe5dcdba3fa079194d08f0 SHA-1: 6b36ad77fc2be069b51c165ed71d09f5ba4b227b SHA-256: 9552fe4941f0e98cb6a81bed628b035571243f78ae64e8aec2a7028cc3a08602
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are SEO-themed and point to potentially malicious PDF files. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or malware distribution. The embedded URLs suggest an attempt to redirect the user to compromised or malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/wix?keyword=geography+of+the+panama+canal+worksheet+answers
    • https://cdn.sqhk.co/kapumikogux/chjtjSL/matal_dance_dj_song_2019.pdf
    • https://cdn.sqhk.co/lojibuwe/je0gggi/the_wonder_weeks_app_price.pdf
    • https://fazerirusabutef.weebly.com/uploads/1/3/1/3/131381144/puwisagikapope.pdf
    • http://catsism.com/bloons_td_5_unblockedssyr8.pdf
    • https://wexasubofuxumeb.weebly.com/uploads/1/3/2/7/132740188/1518957.pdf
    • https://tubolapibakosi.weebly.com/uploads/1/3/4/8/134872187/6847006.pdf
    • https://vususutuf.weebly.com/uploads/1/3/4/6/134634118/1999190.pdf
    • https://cdn.sqhk.co/xutujipux/fGhfOWn/zowudenefigiporatisib.pdf
    • https://cdn.sqhk.co/wadupaxi/Tjchg87/mango_fruit_cutter_from_tree.pdf
    • https://cdn.sqhk.co/matapolid/5BjhXoE/game_of_summoner_apk.pdf
    • https://cdn.sqhk.co/gasawivu/hf3jiYM/superstar_career_dress_up_rising_stars_online.pdf
    • https://cdn.sqhk.co/jigavozef/gdhfYrf/koforilapamut.pdf
    • https://cdn.sqhk.co/geroterunetu/hbRgdEK/6942069663.pdf
    • https://cdn.sqhk.co/sebidurubuze/hjfhefS/34228203382.pdf
    • http://sysfix.ru/puziwavaxizifizewozeb7hpt4.pdf
    • https://waretopaze.weebly.com/uploads/1/3/4/5/134529701/d5e25a071b98b0.pdf
    • http://verifybadgehelp.com/35963338328gfklp.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://eb40363d-1d1f-4170-a897-f23f0f433116.filesusr.com/ugd/2a1429_3d004702ce1c46869d5fee2822000e0b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000db55.bin
adb148400590e1178af13e5e328193f7edcd556cd2d265fce699d9bda4cf37a1
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB55 5716 bytes
font_01_sfnt_off0000eec3.bin
bfb562cd05e2cdf5c56aa0a4836611459fec193abac32c048f80d8dcd0f8d540
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEC3 11416 bytes