Malicious PDF — malware analysis report

Static analysis result for SHA-256 a920779b89e963f8…

MALICIOUS

PDF

79.9 KB Created: 2021-03-21 04:03:15 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4b69affbc74bd991cc6e1d6f70bbf112 SHA-1: 78d3a363274f9c872a837529290127b68aa967fb SHA-256: a920779b89e963f861d559e342df2bd005286ee11ab3fca6cc440cab98310b07
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF was flagged by ClamAV as a phishing trojan and ML classifier indicated high maliciousness. It contains a large number of external links, many pointing to S3 buckets and other domains, suggesting a link farm or SEO manipulation tactic. One of the external links, https://vilenefex.ru/wix?keyword=600+bce+to+1450+ce+timeline, is directly referenced in the heuristics, indicating a potential lure or content delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=600+bce+to+1450+ce+timeline
    • http://keepsufi.space/do_nike_employees_get_discount_on_apple_watchsuhmt.pdf
    • http://akb54.ru/livre_guide_de_la_route_20197i82c.pdf
    • http://shtangelkipokupkiitd.online/kudejifutoseje2e8m.pdf
    • http://plafond.xyz/73904455698g9stg.pdf
    • http://plusstore.pro/655492833543gf3b.pdf
    • http://helplnstagramcontact6088756.com/fakodt8g6d.pdf
    • http://kersita.fun/19305503508okwjx.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/bolovopizonuki/dusuxugowoba.pdf
    • https://s3.amazonaws.com/gomakobez/past_papers_question_bank_sat_subject_test_math_level_2.pdf
    • https://38f9ccf9-db33-4582-994d-0ea518e52d38.filesusr.com/ugd/368de4_14470a2567f147d0b24c7c8eb388caa1.pdf?index=true
    • https://s3.amazonaws.com/tigewibejageju/r12_to_r134a_conversion_kit_walmart.pdf
    • https://s3.amazonaws.com/ninasivol/8286076751.pdf
    • https://s3.amazonaws.com/rovuweraja/why_is_my_whirlpool_side_by_side_not_making_ice.pdf
    • https://c36efdde-2309-4ce2-a10d-b6df2ce12cd8.filesusr.com/ugd/e98059_0bdb7f39e0f24377bf2e368af0217f3f.pdf?index=true
    • https://s3.amazonaws.com/tokatefozude/96616334864.pdf
    • https://s3.amazonaws.com/litunux/adobe_illustrator_templates_free_s.pdf
    • https://s3.amazonaws.com/fazujo/kawogixaw.pdf
    • https://s3.amazonaws.com/padadutiseni/android_floating_action_button_image_size.pdf
    • https://s3.amazonaws.com/jadudusujuje/octopus_pro_apk_indir.pdf
    • https://s3.amazonaws.com/baxekojojexusol/australian_citizenship_test_questions_and_answers_2018.pdf
    • https://s3.amazonaws.com/vabedafozo/gefafowujovokazek.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8e4.bin
e909d2d0b6184eab2b1e2633f1560aae0571cedfc559aa54c98f88a06e5af416
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8E4 5068 bytes
font_01_sfnt_off00010a2a.bin
594684f87b5f69d1c5bd20552f9e17f2277b96cba3253282ddc6ad19535f1f20
pdf-font-stream PDF embedded font (sfnt) at offset 0x10A2A 11344 bytes