Malicious PDF — malware analysis report

Static analysis result for SHA-256 b299eed858896b7d…

MALICIOUS

PDF

75.3 KB Created: 2021-03-25 01:42:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e7214f7ad8a81140dcddcc58ef061f2 SHA-1: 74ad616c6dacd8ded060ff0868dede216fc97546 SHA-256: b299eed858896b7d881d351552b0bf858bfdfb5f7cdf2c7fc41fe4ffda1f3b3b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The heuristic firings point to the creation of a link farm with numerous external URLs, suggesting a phishing or SEO poisoning campaign. One of the embedded URLs, https://kuzutuzo.ru/wix?keyword=crayola+silly+scents+marker+maker+color+mixing+guide, is particularly suspicious and likely leads to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/wix?keyword=crayola+silly+scents+marker+maker+color+mixing+guide
    • https://bosubunu.weebly.com/uploads/1/3/4/6/134693877/2622301.pdf
    • http://crispyset.online/how_to_analyse_your_artwork_gcse1hqgl.pdf
    • http://vovpomnim.ru/sujet_brevet_franais_washington_2019kjy9o.pdf
    • http://swiss-gear.shop/63267263092dbq6x.pdf
    • http://money-team.site/pukuxarefirogumelurubajozept.pdf
    • http://springtea.space/29219950138wrad1.pdf
    • https://gepadagonuvo.weebly.com/uploads/1/3/0/7/130775626/cf1fe2187d6.pdf
    • http://nicechange.space/zenifatuvuxupujavajekq7u8x.pdf
    • https://takijotirodone.weebly.com/uploads/1/3/1/6/131637658/909a1a9b38ba9.pdf
    • http://jushq.pro/hayward_swimclear_cartridge_filter_manualjudqn.pdf
    • http://idealicagocce.site/how_to_replace_mossberg_500_forendn526t.pdf
    • https://femodamokej.weebly.com/uploads/1/3/4/5/134529999/ratunir.pdf
    • http://flipping-car.online/bofimime3wueu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://f039f7e9-c7fa-441d-bf3d-2f0e35d6be10.filesusr.com/ugd/80685d_4500cd7316874aac93243ba3aef0b132.pdf?index=true
    • https://s3.amazonaws.com/nasitevu/1021924023.pdf
    • https://e082b6be-64c0-45f6-a8ff-82b9c6f476f0.filesusr.com/ugd/1479de_8ffe567bd93c458a83a8b06a972d0fdf.pdf?index=true
    • https://uploads.strikinglycdn.com/files/ecf129db-7884-4468-9f66-8acef69a448f/exide_battery_charger_price.pdf
    • https://uploads.strikinglycdn.com/files/c7de2e98-e4d4-48e1-b185-1ae97610b231/39835965899.pdf
    • https://uploads.strikinglycdn.com/files/cbaea601-7d29-4387-8701-32c862a14204/bufeludoravu.pdf
    • https://s3.amazonaws.com/padosumifubobo/dough_sheeter_for_sale.pdf
    • https://s3.amazonaws.com/kukupunopedon/vekotokigix.pdf
    • https://a1c9bafd-2917-4c1b-b79c-a4b44a941470.filesusr.com/ugd/f0f215_05be4088454e4d1392da3027ab392d6b.pdf?index=true
    • https://528a8416-53f4-4693-bcf0-540471887af1.filesusr.com/ugd/c3aa89_2cdaed85c9fe4c159c9dac1101dda45c.pdf?index=true
    • https://d19688e0-347f-4d9d-8cb3-d47c6e049f3d.filesusr.com/ugd/c618e9_28ab28dc03ef4e6aa47b39e576a8acbc.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e691.bin
469bd3c9699e041a9f1f491fc6f4104dbef2cc20f14d6cd28929bd844ccef7cb
pdf-font-stream PDF embedded font (sfnt) at offset 0xE691 5400 bytes
font_01_sfnt_off0000f8df.bin
464e5db6cd2d295d8c142724f97fec35fc6618957392dab06ceee8b68ca9c18c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8DF 11428 bytes