Malicious PDF — malware analysis report

Static analysis result for SHA-256 af9c572b51931fa5…

MALICIOUS

PDF

74.8 KB Created: 2021-03-11 13:40:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 783b10d1d3ab97172adc9958cf4ab5d6 SHA-1: 6f2f8e9106139210c8cdc58f0a47be7fe1edfbef SHA-256: af9c572b51931fa597fc73ab62bae4e7ef3e72b8bd3b2a6ecd9562eb3dbc6f01
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file contains numerous external links, a common tactic for phishing or distributing malware. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of generated links, suggesting an attempt to create a link farm for SEO manipulation or to host malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware delivery via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=cost+accounting+question+paper+2020+pdf
    • https://cdn.sqhk.co/rojarimeg/OhabicT/98509369789.pdf
    • https://lapaluletegole.weebly.com/uploads/1/3/4/6/134679291/385c181c73ac.pdf
    • https://mewejubakokexal.weebly.com/uploads/1/3/2/6/132681976/3540251.pdf
    • https://kuzogirig.weebly.com/uploads/1/3/4/7/134748708/5723897.pdf
    • https://cdn.sqhk.co/kafevinuva/lgh5XwY/zombie_prison_escape_walkthrough_written.pdf
    • https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/4068487.pdf
    • https://cdn.sqhk.co/tobijoge/bja7jj5/the_wolf_among_us_traduccion_espanol_epic_games.pdf
    • https://dedolodaramolon.weebly.com/uploads/1/3/1/4/131455072/6e030a7a2840.pdf
    • https://cdn.sqhk.co/joduragenep/iibIie2/bowling_islands_rothenfeld.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://8dfdba76-182f-4dc4-9dda-37a8c8d09dc9.filesusr.com/ugd/4ae4db_1e89448f845140f78ea24e692bd288fc.pdf?index=true
    • http://tepijivazijovij.epizy.com/business_analyst_online_program_canada.pdf
    • https://3e1ae61b-6b68-46dc-8a90-d1c7a5b9f91c.filesusr.com/ugd/b8bbd7_1978c70ae92d47e9a795bc1015797e6d.pdf?index=true
    • http://wijopimitiraze.epizy.com/weather_report_nyc_now.pdf
    • https://aabf49e0-5477-4fd2-8456-a986ef8f2a87.filesusr.com/ugd/9e14ca_bddbaddbc5a44503bd0eab949fedd493.pdf?index=true
    • http://segurixuzek.myartsonline.com/26526269115.pdf
    • https://f33d1b56-f518-462b-b61f-c1b5c1ba661c.filesusr.com/ugd/1c44ce_0c5456f2d22c4e6e94ccc37440da4fbb.pdf?index=true
    • http://wekujugom.epizy.com/42333747993.pdf
    • https://b9e1b105-38e0-4bbf-baad-90de1e2021e1.filesusr.com/ugd/432b07_8411a79670a542c1a42de1db0f6576b8.pdf?index=true
    • https://d8ec88ce-93b1-4b83-b294-7016fd5b5063.filesusr.com/ugd/366252_77839d05ffba40a6a42361a40edcd474.pdf?index=true
    • http://sofidusujewa.epizy.com/tubodonalavasufabuki.pdf
    • http://pabewuvuxaf.onlinewebshop.net/whats_the_difference_between_pass_by_reference_and_pointers.pdf
    • https://f26e6bca-ce10-4524-9610-ed5ef7c8d48b.filesusr.com/ugd/ac8c68_78e52ad71d434f0e95dd9eadb295a229.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e80b.bin
de2836bc2b279dcd7ac667bf368e56768edeb638a38a05f3ac19f303e962c48f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE80B 5596 bytes
font_01_sfnt_off0000fb17.bin
07eb74fccfd0918b2c5e4563ed6963d971bb06a30dc5dae8e4a15aba6e84da2e
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB17 10116 bytes