Malicious PDF — malware analysis report

Static analysis result for SHA-256 b628b3ed4b9b43dd…

MALICIOUS

PDF

86.2 KB Created: 2021-02-22 18:02:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cb82eada52a4dcfe372209a230f6fce0 SHA-1: 758b92e437918a5fbf6edca582862246fd6de675 SHA-256: b628b3ed4b9b43dd1e788ae2baa65fae253028701e735bfba37fc61fec68cf68
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file was detected as malicious by multiple heuristics and a machine learning classifier, specifically flagged as a phishing trojan. It contains a large number of external links, many pointing to PDF files, suggesting a link farm or redirection mechanism. While no scripts were explicitly extracted, the PDF format can embed JavaScript, and the presence of external URLs indicates an attempt to direct the user to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=roman+numerals+copy+and+paste+font
    • https://static.s123-cdn-static.com/uploads/4384632/normal_5febc0276a33b.pdf
    • http://semengergel.ru/philip_b_crosby_aportacionesot5l9.pdf
    • https://lexolegav.weebly.com/uploads/1/3/5/3/135350326/5717604.pdf
    • https://cdn.sqhk.co/dexizajifu/ju8L4ia/drive_by_truckers_the_new_ok_lyrics.pdf
    • https://cdn-cms.f-static.net/uploads/4378152/normal_60237063b7293.pdf
    • https://cdn.sqhk.co/ripalufix/bVo1qFF/turbo_racing_3d_mod_apk_hack_download.pdf
    • http://nukicew.xyz/karosadf2tr2.pdf
    • https://cdn.sqhk.co/xubupigegi/cjsrphg/vafuwotabefasorujavo.pdf
    • https://cdn-cms.f-static.net/uploads/4369179/normal_60131a8a9b3b1.pdf
    • https://cdn-cms.f-static.net/uploads/4404121/normal_6009ed85c000e.pdf
    • http://sewonmedix.ru/zomasuxofekurera6jjms.pdf
    • https://cdn.sqhk.co/mukutosi/sRZgchg/41103063739.pdf
    • https://static.s123-cdn-static.com/uploads/4479462/normal_5fe1c8034906a.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/nosepevozux/jonugumakixevefosa.pdf
    • https://s3.amazonaws.com/punurum/cisco_meraki_dashboard_configuration_guide.pdf
    • https://s3.amazonaws.com/zewimu/anxiety_disorder_definition.pdf
    • https://s3.amazonaws.com/mozedijiz/centric_brands_email_format.pdf
    • https://s3.amazonaws.com/jenagubadopi/bhimsen_joshi_songs_free_kannada.pdf
    • https://s3.amazonaws.com/kobivimelelo/79574400264.pdf
    • https://s3.amazonaws.com/vobuturinivi/91873254485.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec6c.bin
8e40c08212c3a1a683453e7bf50c148faf7de896ae9ac5a9c705656639f909ee
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC6C 5412 bytes
font_01_sfnt_off0000feca.bin
c7a78baaa3cb2bd2cc3150d48d895d20f43b04edcbacf866028882f536b6921d
pdf-font-stream PDF embedded font (sfnt) at offset 0xFECA 10592 bytes
font_02_sfnt_off0001230b.bin
14a76fa24129809161f4f8fa6b720451e2cb9b09c11bfd39778f3104feffe27d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1230B 17060 bytes
font_03_sfnt_off00013b0b.bin
5686cb655288f55acc831cd8e71fe4fdd997c213a9cb5e03b21efbf5f1b6590f
pdf-font-stream PDF embedded font (sfnt) at offset 0x13B0B 6252 bytes