Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ac09ef58ae52eee…

MALICIOUS

PDF

76.0 KB Created: 2021-03-02 16:26:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2786649a5d3d9d41b48b52317aa55df0 SHA-1: 1aca444125e53ab2f365d06d65f052db25de3974 SHA-256: 9ac09ef58ae52eeec0eb69dd5df60739104f868d48b95b8375aae86bf5ebb9a8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a significant number pointing to link farms and potentially malicious domains. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external PDF links, suggesting an attempt to distribute or redirect users to other malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware delivery via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=the+blue+book+construction+complaints
    • https://static.s123-cdn-static.com/uploads/4490250/normal_5feb177f6a4fa.pdf
    • http://beririka.scienceontheweb.net/spare_parts_joshua_davis.pdf
    • http://ladekepevij.mygamesonline.org/25579210969.pdf
    • http://giviwopifa.22web.org/fawepo.pdf
    • https://bikezurikol.weebly.com/uploads/1/3/4/6/134612173/molonakit-tijirovuwo-rudelidomudu.pdf
    • http://zozuwax.66ghz.com/sesuz.pdf
    • http://sowopezamiw.medianewsonline.com/what_is_the_meaning_of_the_name_tanya_in_hindi.pdf
    • https://kokubuzo.weebly.com/uploads/1/3/4/0/134017800/zenixubev.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://rakemexovujepez.epizy.com/38123352143.pdf
    • http://vovuvap.rf.gd/garmin_vivofit_jr._2_fitness_tracker_review.pdf
    • https://s3.amazonaws.com/jeromisixinolib/ugandan_local_gospel_music.pdf
    • https://s3.amazonaws.com/redegelesibif/how_to_pray_to_get_your_husband_back.pdf
    • https://s3.amazonaws.com/zodawanuror/teveledederixumeribovo.pdf
    • http://sitafefisoju.atwebpages.com/toilet_tank_not_filling_dual_flush.pdf
    • https://s3.amazonaws.com/rakabexozu/firefox_browser_android_slow.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df2c.bin
e9f597de56315954f1187a1c863e7c20b9a1e83d27819636f9449fbe6cf7eacc
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF2C 5208 bytes
font_01_sfnt_off0000f0a5.bin
ce2172a6cfdd1e615deb8ac82c98ee3daae50ba4c78d66c0669f952b0582ac0e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0A5 10528 bytes
font_02_sfnt_off0001147e.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1147E 4324 bytes