Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0d09e76071ef437…

MALICIOUS

PDF

76.6 KB Created: 2021-05-30 22:55:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 81c1db4b9e079b4814cdf0a6336350c4 SHA-1: 5f8995d6a6c0d2a6128cc04d932322926ddf442f SHA-256: b0d09e76071ef437fa1ce74e5d098cfa5b8fa9e2e2e094d34bd548e7391e8be8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for phishing or SEO spam. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of links, and the primary URL suggests a lure related to a specific book title. ClamAV detection as 'Pdf.Phishing.Trojan' further supports a malicious classification. No scripts were extracted, but the presence of many external links points to a redirection or download attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/strik?utm_term=encyclopedia+of+hinduism+11+volumes+pdf PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4486975/normal_5ff1f3bc7d810.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4465564/normal_6067b6a41f6b6.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451545/normal_6029f8c82a5c9.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4416143/normal_5fc6f14354d78.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366969/normal_6056f5a2d18ea.pdfIn PDF document text
    • https://xigujevaw.weebly.com/uploads/1/3/4/7/134701692/5a4b9266.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4460241/normal_5fc812ddc82ef.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4410703/normal_606e615894aee.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4373779/normal_604153cc341b3.pdfIn PDF document text
    • https://sasadopebob.weebly.com/uploads/1/3/5/3/135324308/918acbec8a4e27.pdfIn PDF document text
    • https://static.s123-cdn-static-d.com/uploads/4462727/normal_60b2788f9f30a.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4469c8d-990c-429b-b13e-347d9bee89ee/casio_twin_sensor_sgw-100-2bcf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9c809c85-da0b-4cc1-b6e2-ec844071d89e/nabutebilipozeri.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a9b5fab9-c5b7-411c-906c-9ada773ed5d9/how_to_put_bobbin_in_brother_ls-1217.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e300cca0-d451-437f-8c17-891a7ff0acc6/how_to_build_great_sentences.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/79098ff9-0ca3-4aec-8701-99e5e0c639fc/kotoradi.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ddadac17-efa2-4fa0-8b1b-9180cfcde04f/formato_de_avaluo_de_casa-habitacion.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b5ed8c71-b13a-45e9-8f20-2261182b4531/64133380773.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5c8610c5-8886-4be5-9691-e225f11c0bad/84228955321.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec08.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEC08 5472 bytes
SHA-256: 54aa221ee8bfe5e2cb9a10b4e7b3d5896b26ec27d3aea132279f3abdfc59ebeb
font_01_sfnt_off0000fea0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFEA0 11340 bytes
SHA-256: d27cadc4e8188f4967ad4de4d3863908a2cc4f7cb129a9aacad6fd816127ad34