Malicious PDF — malware analysis report

Static analysis result for SHA-256 95755c512137a01b…

MALICIOUS

PDF

66.2 KB Created: 2021-03-05 13:53:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 30bc2974295844ef1f42e73579a00781 SHA-1: d4dc8bb4be2d513c9e17e94c14c10f557fe2209c SHA-256: 95755c512137a01bae3b2a0cae1a23cb7decb024ea32d621602bf5a82d0b6b19
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying it as a 'PDF_SEO_LINK_FARM'. One of the primary external links points to 'vilenefex.ru', which is suspicious. While no scripts were explicitly extracted, the PDF structure and the presence of many external links suggest an attempt to redirect users to malicious sites, likely for phishing or to download further malware. The ClamAV detection as 'Pdf.Phishing.Trojan' further supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=gameboy+color+roms+pokemon+crystal
    • http://runmasten.online/19549767072az3id.pdf
    • http://didavixakodix.22web.org/4313926266.pdf
    • http://armlur.space/nimona_book41j2t.pdf
    • http://abwaab.su/jabees_firefly_2_earbuds_reviewqudei.pdf
    • http://amsidisi.xyz/great_outdoors_smoky_mountain_series_smoker_partsp8vqq.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/ravuxudibure/kgb_file_archiver_free.pdf
    • https://s3.amazonaws.com/dujepav/mystic_lake_montana_fishing_report.pdf
    • https://s3.amazonaws.com/debamijizozexo/appcleaner_for_android_review.pdf
    • https://0ef2f354-78a3-4528-990c-72f69c86fc6a.filesusr.com/ugd/6a0da6_5371eafceb3b462793b9624acc5ce562.pdf?index=true
    • https://50b44c92-959e-4a15-bf83-93d6b2b518d6.filesusr.com/ugd/3ed44c_264e729f4fe14bac971d73d4560a1b4f.pdf?index=true
    • https://b54663a3-ff9d-4122-b75c-69b71428c9b0.filesusr.com/ugd/cfa91a_3a2af3766bb54c048e3d6d1882452def.pdf?index=true
    • https://s3.amazonaws.com/latufenaw/xexemokuloli.pdf
    • http://tagutibebik.rf.gd/pokemon_emerald_walk_through_walls_hack.pdf
    • https://s3.amazonaws.com/vuxalirudidel/45257216161.pdf
    • https://4b4b92a8-4ac5-4030-97d5-af0917f8c077.filesusr.com/ugd/0251f0_2e9fe15930894a38b314f785eccb4e0e.pdf?index=true
    • https://s3.amazonaws.com/retisovojor/harry_potter_cast_luna.pdf
    • https://s3.amazonaws.com/mizeteb/google_maps_platform_blog.pdf
    • https://a1d3e036-d9a1-4be1-9d2f-eedbb581cb22.filesusr.com/ugd/3ce946_421cd68054ba43d7a4b609126fc20a4c.pdf?index=true
    • http://voxokemawabam.rf.gd/bumapukumadujezevaguwatur.pdf
    • https://6f81cef9-66a2-447d-9e1d-4c0427ef15c5.filesusr.com/ugd/4d935e_0e8d0f72fd834ced952189ea393b1899.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c720.bin
cf9de43bd86715649d27453413f264ad742990b646688d6777a4af343da199fe
pdf-font-stream PDF embedded font (sfnt) at offset 0xC720 5416 bytes
font_01_sfnt_off0000d97d.bin
a7c4b37e5df3d5739076a59cd9ef856325951f5c09e43e01b431d75553be2390
pdf-font-stream PDF embedded font (sfnt) at offset 0xD97D 9984 bytes