Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2a271fa280e0cc1…

MALICIOUS

PDF

76.8 KB Created: 2021-03-23 01:06:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 09ba78d032e585571e2c6cf14ce8f8f2 SHA-1: 7087befd05e468e7a4963cb48ca5bc802dabaeeb SHA-256: b2a271fa280e0cc129b7cd04a59869c0f7e4e05d233c7e3c96ab9c25e43edd62
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The primary URL points to a page that appears to be related to 'organic chemistry pdf', suggesting a lure. While no scripts were explicitly extracted, the PDF structure and the high ML confidence score indicate malicious intent, likely related to phishing or malware distribution via the linked PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/award?keyword=name+reaction+in+organic+chemistry+pdf
    • https://zedabobosarafon.weebly.com/uploads/1/3/0/8/130813357/fozepeguvamiru.pdf
    • https://cdn.sqhk.co/waxolulum/fWS0sij/41920139019.pdf
    • https://static.s123-cdn-static.com/uploads/4427076/normal_5fdf2ed2a505e.pdf
    • https://cdn.sqhk.co/mozoposowi/ggg99oP/space_simulator_mod_apk_unlimited_fuel.pdf
    • https://cdn.sqhk.co/tofigidukug/bggjhG4/k-_pop_idol_producer.pdf
    • https://cdn.sqhk.co/dolafita/ghjgdjf/ultimate_forest_simulator_boss_battles.pdf
    • https://cdn-cms.f-static.net/uploads/4420608/normal_5fd7894792c33.pdf
    • https://cdn-cms.f-static.net/uploads/4489835/normal_6052f92de3475.pdf
    • https://vepovipozo.weebly.com/uploads/1/3/4/4/134472033/9117295.pdf
    • https://cdn.sqhk.co/kivipemo/CsqibHb/duzibadufefubonatamarukez.pdf
    • https://tiforunu.weebly.com/uploads/1/3/1/4/131437018/kozuzabila-gatepanin-kemagud.pdf
    • https://cdn.sqhk.co/tatomaxeriri/jp1lEKe/nhs_dysphagia_guidelines.pdf
    • https://dowamodugepaxa.weebly.com/uploads/1/3/0/7/130739159/pubomakav.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vapite/healthstream_infection_control_test_answers.pdf
    • https://uploads.strikinglycdn.com/files/30a62632-42f1-4f67-9dbb-04b979a5845d/general_packet_radio_service_tunnelling_protocol.pdf
    • https://s3.amazonaws.com/woxojuxafopuv/mutamukunekesosenojugukiz.pdf
    • https://uploads.strikinglycdn.com/files/53a5c357-b06e-48d6-aa58-9bd885314276/does_nordictrack_1750_have_bluetooth.pdf
    • https://uploads.strikinglycdn.com/files/864b5904-8c50-48e6-9a7e-b6f9a0c998ee/33177783550.pdf
    • https://s3.amazonaws.com/xunilukegez/what_are_behavioral_adaptations_of_a_lion.pdf
    • https://s3.amazonaws.com/bogeguva/attack_on_titan_season_4_episode_3_synopsis.pdf
    • https://uploads.strikinglycdn.com/files/4f6eab7c-a72e-43d5-9aa1-5bb26578cba7/juxinubupajazabemuzo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eab0.bin
2ce18c9be74f3db55f5abd125c6516fe58cf26eff187878fda69d629c371270e
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAB0 5608 bytes
font_01_sfnt_off0000fdaa.bin
73a353ff84045b9d154ff481f5d2205274a982a6ba60902c2d61b4df7e4fac26
pdf-font-stream PDF embedded font (sfnt) at offset 0xFDAA 12172 bytes