Malicious PDF — malware analysis report

Static analysis result for SHA-256 a72965828334d894…

MALICIOUS

PDF

74.0 KB Created: 2021-03-15 09:27:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b598c4b3c20d971220365fc642c46b44 SHA-1: 2b497d878b121792dd5dd523b0f1fa5c7314f5b9 SHA-256: a72965828334d8947f4af6af38f86816b0ebbf9c3bb0b20fc36684f0a309d85e
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic firing for PDF_SEO_LINK_FARM indicating a mass link farm. One specific link, http://lenumizisil.rf.gd/mary_poppins_lyrics_supercalifragilisticexpialidocious_backwards.pdf, is flagged as a random URL. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINK
    PDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=grupos+financieros+de+guatemala
    • http://vonurejawata.iblogger.org/lg_electronics_tone_pro_hbs-750_bluetooth_wireless_stereo_headset.pdf
    • https://cdn-cms.f-static.net/uploads/4391326/normal_602eda4bd7005.pdf
    • https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/woxopidevugefij.pdf
    • http://fikizabeji.22web.org/56543008368.pdf
    • http://gedirobidepud.scienceontheweb.net/71701108276.pdf
    • https://cdn-cms.f-static.net/uploads/4424029/normal_603943051d342.pdf
    • http://verunej.iblogger.org/thoreau_quote_walk_in_the_woods.pdf
    • https://nefupoxuwuridek.weebly.com/uploads/1/3/4/7/134747690/losuv.pdf
    • https://fulojexerewo.weebly.com/uploads/1/3/5/3/135345176/jinageze.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://7ae774ad-b64d-4473-a0b1-aa0db1e39e83.filesusr.com/ugd/3e7897_c1e2e42525dd4d72be4b660c9eecd17b.pdf?index=true
    • https://3c45aaf8-24f3-4cde-9773-cf44a0a970d3.filesusr.com/ugd/ae7d54_9ff571bb26d940ea9e11d2cbfedb9410.pdf?index=true
    • http://vujapaporetakik.epizy.com/reproduccion_de_las_angiospermas.pdf
    • http://wiwosotu.myartsonline.com/who_moved_my_cheese_overview.pdf
    • http://lenumizisil.rf.gd/mary_poppins_lyrics_supercalifragilisticexpialidocious_backwards.pdf
    • https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_6fff25fea089486185068a3bb0f7ab35.pdf?index=true
    • https://c3438639-6a75-4920-aa4f-d1e0b619354f.filesusr.com/ugd/3be3a7_8d5056bd05574b06b71cb9abdf49563d.pdf?index=true
    • http://wisituvoj.epizy.com/is_python_a_good_coding_language_to_learn.pdf
    • https://656adf98-7a81-40bd-8d0f-2b9c27d09201.filesusr.com/ugd/268ab1_4d8ff86ee6de4249905adfe83b9b15e4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e25c.bin
cd5cec0c0028d9d2c6a3f5be5db13d18b5abbc709ad40437a3671b9f8273f221
pdf-font-stream PDF embedded font (sfnt) at offset 0xE25C 5508 bytes
font_01_sfnt_off0000f504.bin
f0ac767805b7bca57db0d17449675bd644cbc8ddf382e8ff967c7cfbec36ca85
pdf-font-stream PDF embedded font (sfnt) at offset 0xF504 11604 bytes