Malicious PDF — malware analysis report

Static analysis result for SHA-256 b59b721fd515a30b…

MALICIOUS

PDF

82.4 KB Created: 2021-04-01 17:46:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-22
MD5: 971f0c4b292de87e2127a27bee2e07a2 SHA-1: 3295306d339d0755184a627bfba0924a8257b822 SHA-256: b59b721fd515a30b1d9da3874b9f1c6cecc03356ecba3d4e120056f69e1e54d3
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=dot+net+framework+interview+questions+and+answers+for+freshers PDF link annotation
    • http://superheatbelt.xyz/88571546299m4rg5.pdfIn PDF document text
    • http://blognews.top/journey_to_the_west_movie_download_in_tamil0xj8r.pdfIn PDF document text
    • http://d2-club.ru/jotonoboguv37od3.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4476274/normal_600cafb786148.pdfIn PDF document text
    • http://skywonder.space/5057950270m2ifq.pdfIn PDF document text
    • http://rineset.xyz/74635323526vyu8b.pdfIn PDF document text
    • http://mmuuue.space/crazy_climber_2frbo5.pdfIn PDF document text
    • http://dominis.xyz/how_to_lose_weight_on_chest_and_backqeema.pdfIn PDF document text
    • http://vzruvayarttraff.xyz/zepotemisibexakevedozxexr9.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4407069/normal_60488d8179619.pdfIn PDF document text
    • http://findattime.com/remstar_m_series_filtersjjdmz.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://8488b7ac-84bc-45ae-88ed-26841205fc59.filesusr.com/ugd/7cda3c_c657e46b3f72417f8b94363a4aa0d4f4.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/figidireki/devevitap.pdfIn PDF document text
    • https://s3.amazonaws.com/zusevamasor/kapigaxawi.pdfIn PDF document text
    • https://s3.amazonaws.com/zijivevip/18164188343.pdfIn PDF document text
    • https://s3.amazonaws.com/faxaxos/gusamufir.pdfIn PDF document text
    • https://s3.amazonaws.com/sepovutapakogaf/feasibility_and_viability_study.pdfIn PDF document text
    • https://c33c3ce4-fa2f-4f19-9477-7a801b41b29e.filesusr.com/ugd/ebbcbd_3477423aea2e407d86e4624c2847c930.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/mawesenasijoser/bozareriloxerisemedapo.pdfIn PDF document text
    • https://s3.amazonaws.com/luramamelolem/league_of_legends_pick_em_guide_2018.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010530.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10530 5456 bytes
SHA-256: 48fb9ebe0235b7cbe6ef087e950967968fead51161fb0a00cac8c086d339cb24
font_01_sfnt_off000117b6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x117B6 10924 bytes
SHA-256: d96dcc87c108c099461b1e6a731c4cc26339784152e3bf6c3639d1a3d66b11ab