Malicious PDF — malware analysis report

Static analysis result for SHA-256 982bce675a440f5b…

MALICIOUS

PDF

80.9 KB Created: 2021-03-28 18:03:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2ab5fe8a9348736370d418693bdd6f94 SHA-1: 43f035ba7913e0c3a8700136435f1fcf9f358da4 SHA-256: 982bce675a440f5b5126e7507ced1fc28b2dde0abc3d15ac95cf11f1e3f01f28
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a link farm, suggesting a malicious intent to redirect users. ClamAV detected the file as 'Pdf.Phishing.Trojan', and ML classification strongly indicated maliciousness. While no scripts were directly extracted, the presence of numerous external URLs points towards a phishing or SEO manipulation attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/123?utm_term=dc+motor+arduino+datasheet
    • http://fibilif.iblogger.org/south_west_gauteng_college_application_form_2020.pdf
    • http://jokebixa.22web.org/lozofof.pdf
    • https://cdn.sqhk.co/xoraxuvonaf/dgigdhb/cirrosis_hepatica_fisiopatologia_2017.pdf
    • https://cdn.sqhk.co/nemalerute/gigcjcN/man_in_the_mirror_book.pdf
    • https://ranedesipa.weebly.com/uploads/1/3/1/3/131398497/1647612.pdf
    • http://zeweduzu.iblogger.org/developer_options_android_9.pdf
    • https://cdn.sqhk.co/babakobesuxe/eFhgiav/business_description.pdf
    • https://cdn.sqhk.co/vakolitakap/JhbDgd8/14908293268.pdf
    • https://xilamebi.weebly.com/uploads/1/3/4/5/134598653/7a5cd19f14801d.pdf
    • https://cdn.sqhk.co/tajalawad/fgjKhcQ/45223640911.pdf
    • https://mogeletonedilo.weebly.com/uploads/1/3/1/4/131482944/zixudaxixupozigali.pdf
    • https://cdn.sqhk.co/bikezuku/8gcHihq/juxijekix.pdf
    • https://bupedokan.weebly.com/uploads/1/3/1/6/131607930/gakoten-wajamu-porufalapewuw.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://1c8fadd7-09eb-4d2b-9d42-8e747ba5ce52.filesusr.com/ugd/60625b_77959969018648b1a1c89a560b4ea311.pdf?index=true
    • https://c8d0f166-86fd-441b-8df5-aa5e6c6c7644.filesusr.com/ugd/f4b3af_7adc6b89fc5740c0907415c96cb65ecc.pdf?index=true
    • https://s3.amazonaws.com/jutenojamega/google_play_store_services_apk.pdf
    • https://s3.amazonaws.com/forupokisip/y8_car_games_free_for_pc.pdf
    • https://s3.amazonaws.com/gurafoga/66286261499.pdf
    • https://s3.amazonaws.com/belapawerezuju/ablowitz_fokas_complex_variables.pdf
    • https://0f285ee0-1b14-49a2-8a3e-060a2db94812.filesusr.com/ugd/4bf67f_a40d7eca4cfe4543b037f26855f1ea7e.pdf?index=true
    • http://pafixorofabeza.epizy.com/60889926627.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef7f.bin
0908507b63e43c558c1a2bcb640e93a9ee87fd7ba8d6f59cf56a903f7447d3e4
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF7F 5028 bytes
font_01_sfnt_off0001005e.bin
dfbafb0cfbcc15d1637b2fa469fd41430a2dfd761750d127df63b84adf1caa5c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1005E 11220 bytes
font_02_sfnt_off000126cc.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x126CC 4324 bytes