Malicious PDF — malware analysis report

Static analysis result for SHA-256 b0ebfb23e5db5ee9…

MALICIOUS

PDF

72.2 KB Created: 2021-03-13 12:44:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a46b3cd668c45e736e6b5850f5b90e02 SHA-1: 7b89f17f29b14dcc222cb9fc0cfaa9973ccfadd0 SHA-256: b0ebfb23e5db5ee9f21ef711a7540c5221f5ddd0c9f85d889263a7a5d22f96ab
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to direct users to malicious websites. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the overall structure point towards a phishing or malware distribution scheme, likely initiated via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=hibernia+reit+annual+report+2017
    • https://cdn-cms.f-static.net/uploads/4410016/normal_6018051b3f162.pdf
    • https://cdn.sqhk.co/fujotojaxob/iAyjf0p/58381090438.pdf
    • https://cdn-cms.f-static.net/uploads/4380382/normal_60146a814009f.pdf
    • https://cdn.sqhk.co/gofelaxes/i2eMEge/53711910878.pdf
    • https://cdn.sqhk.co/givifevulo/igJKRUo/images_of_television_above_fireplace.pdf
    • https://static.s123-cdn-static.com/uploads/4386839/normal_5fc8c4ddd962b.pdf
    • https://static.s123-cdn-static.com/uploads/4384143/normal_5fe55cd999869.pdf
    • https://static.s123-cdn-static.com/uploads/4412379/normal_5fdd78a3acd9d.pdf
    • https://cdn.sqhk.co/lumolixuwo/rhjYibP/50441190264.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/849a15f8-ad03-430a-bf73-08ed8ae55d86/werotiwoxifuzul.pdf
    • https://s3.amazonaws.com/sajezife/6387825669.pdf
    • https://s3.amazonaws.com/waxapoz/assessing_learning_outcomes.pdf
    • https://s3.amazonaws.com/xovajukoxin/72940063423.pdf
    • https://s3.amazonaws.com/nilititonawafim/38970315245.pdf
    • https://7d14b3fe-44ab-47f5-a5a4-fb5d7998febd.filesusr.com/ugd/ba499c_a3d656aff3cc48bb8348c3a2bcc75f60.pdf?index=true
    • https://s3.amazonaws.com/wizomoravazub/abc_tamil_movie_songs.pdf
    • https://uploads.strikinglycdn.com/files/5b2f2fdd-0790-456e-ab5c-91431501dfa8/ice_breakers_ice_cubes_gum_nutrition_facts.pdf
    • https://931f52e6-cb68-4a93-8e02-54808d33f8b6.filesusr.com/ugd/6290de_d5a5db74e9e949b184e412cf7adccdef.pdf?index=true
    • https://0621cc9e-6449-4e8a-a8bd-baee9ad62a2c.filesusr.com/ugd/affb4a_d58c21de7fdb4d2a97d6cc98cad35736.pdf?index=true
    • https://s3.amazonaws.com/bibejovixapis/45452326579.pdf
    • https://s3.amazonaws.com/juduk/adverse_selection_and_asymmetric_information.pdf
    • https://s3.amazonaws.com/zafaronivaj/posaduxadoso.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc39.bin
b500f363a790a6c75148d6020521b49ddd611bfb002bc10d298ecd311adad332
pdf-font-stream PDF embedded font (sfnt) at offset 0xDC39 5140 bytes
font_01_sfnt_off0000edc9.bin
b121d1603008ccbb7636eda111890337fa0aaf70e8132c396e4bd5e1b472d165
pdf-font-stream PDF embedded font (sfnt) at offset 0xEDC9 10992 bytes