Malicious PDF — malware analysis report

Static analysis result for SHA-256 995a05f2f40a2df6…

MALICIOUS

PDF

101.3 KB Created: 2021-02-05 20:12:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-23
MD5: d7461e3bb7e537f61588e07e572ac6bc SHA-1: fc2b19224a7ae0b73134dd728d6881dfd9bfe576 SHA-256: 995a05f2f40a2df6f1c48b42d70b017aedee3a2f2191c8d0f7b9af8a40ed7329
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, including one to 'seumenha.ru', which is flagged as a potential phishing or malware distribution lure. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting an attempt to drive traffic to other sites. ClamAV also detected this file as 'Pdf.Phishing.Trojan'. No scripts were extracted, but the overall structure and link farm suggest a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/aws?utm_term=dht+humidity+sensor+datasheet PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4460055/normal_5ffcbb46e4243.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4374848/normal_5feee11c14d47.pdfIn PDF document text
    • https://gisijenoxumo.weebly.com/uploads/1/3/1/4/131437849/5345778.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385887/normal_600c8a6ade621.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475572/normal_601951f263bc8.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4452199/normal_5fe4790a738ad.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4531523/normal_5ff0f1fe663ae.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4453129/normal_601b0b82304ae.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4480755/normal_6011cd4135966.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4469101/normal_5fec8d88dc8a2.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4374860/normal_5fdcb3968b021.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4403817/normal_5ff08d1814c3f.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413016/normal_5fda03ca6964a.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4418399/normal_5feb180b6b645.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4496151/normal_5ff8edc99e158.pdfIn PDF document text
    • https://varudigenaka.weebly.com/uploads/1/3/4/5/134597471/mogolobeloserugew.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4485321/normal_5ff8c9a3df503.pdfIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/jinabisura/arms_around_you_video_hd.pdfIn PDF document text
    • https://s3.amazonaws.com/wozoxub/brother_in_arms_2_mod_apk_obb.pdfIn PDF document text
    • https://s3.amazonaws.com/fejakixoweka/cash_drawer_count_out_sheet.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off000133cd.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x133CD 14824 bytes
SHA-256: 01bf1768c4104735adda02eddbd6a85e662a1c4a6c03e6891ae7356ae2fc5a88
font_00_sfnt_off0001179c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1179C 3060 bytes
SHA-256: ace1947e1eb6bf471eb1c049b6a98886d23bdfddb32be2a753a5d617c4c4343d
font_01_sfnt_off00012287.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12287 5132 bytes
SHA-256: b090dfe027e271ccf9f11d47424ec68612dd657e97aa962d867396f32301c594
font_03_sfnt_off00015c90.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15C90 12928 bytes
SHA-256: 7c92c286b6da9a020ef94a629f5f5d4129b0eebb1be3cab3f3d0e1a334b19654