Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0874e854efb63b0…

MALICIOUS

PDF

91.1 KB Created: 2021-03-24 12:44:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f51a5e6729d610912850b05e4c83d6ab SHA-1: 124ce31d88f93324d20935b2f58c7bae5f6c343b SHA-256: b0874e854efb63b00420674927af9bd43f3bd33bcf05648a03929cac765a176b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was identified as malicious by multiple heuristics and a machine learning classifier, specifically flagged as a phishing trojan. It contains a large number of external links, many pointing to PDF files, suggesting a link farm or phishing lure. The presence of embedded URLs and the overall structure indicate an attempt to redirect users to potentially harmful websites, likely for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9975

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://resalured.ru/123?utm_term=nokia+8+android+one+rom
    • https://cdn.sqhk.co/mipijotom/bt5LidH/rulanogizezezozedurepe.pdf
    • https://cdn.sqhk.co/guvawatuzax/YQVhajh/domino_s_pizza_club_whatsapp.pdf
    • https://cdn-cms.f-static.net/uploads/4393044/normal_5fd2caca756ae.pdf
    • https://cdn.sqhk.co/migixurej/fgchduV/the_woodlands_umc_loft.pdf
    • https://cdn.sqhk.co/ruradavi/iifhfjd/xuzireja.pdf
    • http://bestita.space/transmission_line_theory_basicsc8n91.pdf
    • http://jilet1.club/chris_bryant_ccnp_study_guide8sywg.pdf
    • http://kadanijojabuf.mywebcommunity.org/sarufilavonodawolupog.pdf
    • https://cdn-cms.f-static.net/uploads/4374188/normal_6027a889b2a41.pdf
    • http://lifeeuro.info/pobamibokada7q6y.pdf
    • http://jenuxijaf.mygamesonline.org/69357483488.pdf
    • https://cdn.sqhk.co/tinolefowi/hGbyiev/tiny_tennis_racket.pdf
    • http://rostov-mobile-doctor.ru/endless_night_novel_downloadtga8q.pdf
    • https://cdn-cms.f-static.net/uploads/4378175/normal_5fdc0bccc7636.pdf
    • http://japamawosoj.mygamesonline.org/32449657210.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.opentle.org
    • http://fedorahosted.org/lohit
    • https://d4e9107b-ea7a-46dd-9434-10729a3140ee.filesusr.com/ugd/2e3df4_1acc9a0101bd4eb18af4281733f8a5fb.pdf?index=true
    • https://a8a2d6b8-6248-42a0-90a4-e25e421c2e59.filesusr.com/ugd/f63f29_e9b64ebe94b34823911306d4c158a640.pdf?index=true
    • https://68fdcf0a-b1f0-4758-9edf-48d2be6d990b.filesusr.com/ugd/ac51ce_06c178fda80c4c1f83122db39be26b9a.pdf?index=true
    • https://b00f38ea-0d13-4519-ab0f-1253f0d03ca0.filesusr.com/ugd/289c5e_909c76fac9ce4ad1894148c6ff26fb12.pdf?index=true
    • https://8b1d1a20-f0f3-43d5-aeb5-704ac988d6c7.filesusr.com/ugd/9dbc1d_2fa0acb420e74c1eb9a3fdc518136bab.pdf?index=true
    • http://gejizejaniwijef.atwebpages.com/12938933880.pdf
    • http://japinoxizidunub.myartsonline.com/sandisk_clip_sport_firmware_download.pdf
    • https://58960a86-a3f4-42d8-866e-ee2cf32068b1.filesusr.com/ugd/1ad962_b423ad6ed7cb49deb089a7c72f8122e8.pdf?index=true
    • https://d25e5d79-f3dc-43ab-8538-58f2f4730235.filesusr.com/ugd/898300_67340512ed9746be8d683e3ac2528544.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8a4.bin
082c89522e4251f0a814862fddf633b1dac669eb780a02580130c1f52bfffe84
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8A4 3312 bytes
font_01_sfnt_off00010485.bin
41cc61949cf614ede4838c56a2b13804cfb5fbf180ee7d0c07334cad330e6170
pdf-font-stream PDF embedded font (sfnt) at offset 0x10485 4988 bytes
font_02_sfnt_off00011564.bin
eca62b72654736461a635ba366d09d794777fd95c58152d2b251becdfce657e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x11564 6640 bytes
font_03_sfnt_off00012701.bin
88a8a50df78f3b4b32e32c91cfdd7337a85aeb778831ce1c518f9fc9a59f3488
pdf-font-stream PDF embedded font (sfnt) at offset 0x12701 12804 bytes
font_04_sfnt_off000150d7.bin
a12908a88df35a7e9eb57470e9a94a806bb52df392ce88a62d07cba2b79b9044
pdf-font-stream PDF embedded font (sfnt) at offset 0x150D7 2832 bytes