Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae203f7b80802caa…

MALICIOUS

PDF

89.7 KB Created: 2021-03-18 14:48:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b9b0866c7c924a9debee6f70a3c209ed SHA-1: 74af9873aafb5cab30be5aa3a804e9645e06323c SHA-256: ae203f7b80802caa60a7a5900c21cadc38dcfbe3305c64213dc07f9d961d0582
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with one prominent URL pointing to a site offering a 'textmail app for android'. This suggests a phishing or malware distribution attempt. The ClamAV detection and ML classifier further support its malicious nature. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of malicious intent, likely involving redirection to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9947

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=textmail+app+for+android
    • http://useporte.xyz/how_to_descale_your_keurig_k_supreme5me1a.pdf
    • http://fibubomalinod.22web.org/56235579765.pdf
    • http://polypak.site/rimofexiwukavefusdbodq.pdf
    • http://dipazekonowa.mypressonline.com/55948579831.pdf
    • http://rilomenininun.getenjoyment.net/agresti_categorical_data_analysis_2nd_edition.pdf
    • http://vebifitapex.mypressonline.com/wikusotut.pdf
    • http://xefapase.iblogger.org/paduwogenadewatebu.pdf
    • http://dazolovegom.mygamesonline.org/wd_tv_hd_media_player_firmware_upgrade.pdf
    • http://docita.fun/95013290536brlre.pdf
    • http://clipshd.design/romasatefuvaro8u3s0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/bisegilupuf/sjogren_s_syndrome_treatment.pdf
    • https://9e730ba1-499c-413e-9a09-8a81f8121270.filesusr.com/ugd/0a0016_679d293abb7e4045bd576d58384303be.pdf?index=true
    • https://9fb0fece-6c2a-4f8b-8ff1-5d9ea67f5ee7.filesusr.com/ugd/f6a907_be4c38061f0a430aba0b1351c4affa3a.pdf?index=true
    • https://s3.amazonaws.com/perurulexi/81732100195.pdf
    • https://s3.amazonaws.com/tudawufed/19750612648.pdf
    • https://s3.amazonaws.com/visagogijulep/45135432021.pdf
    • https://s3.amazonaws.com/lososimap/html_css_templates_without_bootstrap.pdf
    • https://s3.amazonaws.com/zosevid/13794215831.pdf
    • https://s3.amazonaws.com/suxiweke/docker_image_version.pdf
    • http://zonafikepejese.onlinewebshop.net/dixopakixavelotameba.pdf
    • https://a8a2d6b8-6248-42a0-90a4-e25e421c2e59.filesusr.com/ugd/f63f29_ffab8201ca1d4bd684f7e67641e3921f.pdf?index=true
    • https://c0b8f06b-4e98-4d3d-89ef-2f08caba629a.filesusr.com/ugd/0c8cc8_34d90b85f6c44377a6c7f8444db0764f.pdf?index=true
    • https://46b09160-81f9-4cb3-9cca-f7b5b0c0229e.filesusr.com/ugd/179cc6_e9ade52051be48938c4d7ae53bf75e7c.pdf?index=true
    • http://sodexodape.rf.gd/cbse_guide_class_11.pdf
    • https://s3.amazonaws.com/foneniz/rubofizunamapodemap.pdf
    • https://s3.amazonaws.com/pulujolatepuv/how_would_you_describe_a_window_in_the_kitchen_eating_area_answer_key.pdf
    • https://s3.amazonaws.com/wezukep/fadiwitanarujamosubule.pdf
    • http://favilogas.rf.gd/thankful_answered_prayer_quotes.pdf
    • http://feramivo.rf.gd/newsletter_microsoft_word_templates_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000115fe.bin
3e7a5c4673ae190a79dfeca75a756332e25fdf1a725cc604e97b17a034c6926f
pdf-font-stream PDF embedded font (sfnt) at offset 0x115FE 5028 bytes
font_01_sfnt_off000126ff.bin
9e1b5a22a4e812d8e40943107ae772de410627a1b530a5785d852530b9e163fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x126FF 2284 bytes
font_02_sfnt_off0001313f.bin
25b56d196791c8cfdd952d37ff4f23eac2bcaa2195708339331b9ddefe923e7a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1313F 11608 bytes