Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6cfd04d4e428180…

MALICIOUS

PDF

86.6 KB Created: 2021-03-27 21:48:37 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0e23aa20fbeab2c91df870cef8d9b4f0 SHA-1: ed86e18e95ae18d7df7996ebebff24252e6065ee SHA-256: b6cfd04d4e4281802c29596db7c3255bb4d62dde73fe9269cb8c482536608ac9
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying it as a PDF link farm. One prominent URL, https://lozipotod.ru/award?keyword=bomb+calorimeter+practical+pdf, is presented in the document body, suggesting a lure to download further content. The ML classifier strongly indicates maliciousness, and the presence of embedded links points towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=bomb+calorimeter+practical+pdf
    • https://static.s123-cdn-static.com/uploads/4461767/normal_5fde87a12c4b3.pdf
    • https://static.s123-cdn-static.com/uploads/4478414/normal_5fe5b45502e69.pdf
    • https://cdn-cms.f-static.net/uploads/4409255/normal_600fdb9fac457.pdf
    • https://cdn-cms.f-static.net/uploads/4384142/normal_60250a568a688.pdf
    • https://cdn-cms.f-static.net/uploads/4471723/normal_6035c31e7b00e.pdf
    • http://luzolala.iblogger.org/fagavagifupukowofedizupox.pdf
    • https://cdn.sqhk.co/bamazaludez/eN4zosh/japamujakenogupipo.pdf
    • https://cdn.sqhk.co/xivomojuf/0mjf7j5/axes_io_mod_apk_an1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://zokivobadid.rf.gd/60427822997.pdf
    • https://8ee4d174-735f-4cd7-9396-c3a65dbcc337.filesusr.com/ugd/5ac313_386a7530ce754a968c98a68268e0a53e.pdf?index=true
    • https://6648aa49-deb3-4d6f-81a8-a63cc7a297fb.filesusr.com/ugd/38eac1_802e89dfce104089bac386253afe87cc.pdf?index=true
    • https://95049c82-e412-4913-a0b0-e03e83d5170a.filesusr.com/ugd/127d6e_167f7e87ea4c457c89176765086c3537.pdf?index=true
    • https://s3.amazonaws.com/nuxomigo/daxurezanez.pdf
    • https://s3.amazonaws.com/gapuruxumeg/pupotapezebomubuxodupi.pdf
    • https://8dac4d01-2cd1-45d2-8b5f-6005f802adc9.filesusr.com/ugd/1f96ce_81847e6b4ffa4d08a248ae3003d11c4f.pdf?index=true
    • https://d1ee23ee-9ccf-45b0-80ef-1e1ff1f657c4.filesusr.com/ugd/9ef0c3_ebdaf651b96a44d3aa715e9dcef763e2.pdf?index=true
    • http://baxiziroj.epizy.com/american_truck_simulator_2_apk_in_android.pdf
    • https://16012499-1299-48b0-8cdd-5f23a7749958.filesusr.com/ugd/fafc38_12765919c7c948dba8a7bb005cc9e055.pdf?index=true
    • https://4ad55601-b8ab-4ae0-bc0e-e90069072326.filesusr.com/ugd/3aca14_f4d5bb8670114c1cb0c49b6b62551bb5.pdf?index=true
    • https://6baea7ca-81e4-4a11-8410-716433a99462.filesusr.com/ugd/764aaa_39d7a23cf0ad4b1f9615bdbfcbc93160.pdf?index=true
    • https://s3.amazonaws.com/tuxenipup/14167958048.pdf
    • https://s3.amazonaws.com/povelenavuviw/mizavuzifafamefanomuva.pdf
    • https://s3.amazonaws.com/xurixado/home_depot_ceiling_fan_size_guide.pdf
    • http://mukaxasapezaw.rf.gd/why_does_my_mitsubishi_tv_keep_shutting_off.pdf
    • https://28f2c00a-638b-45ec-8848-4d649cb6aba9.filesusr.com/ugd/946f28_278c41b07f6943f2a6e12a101ad50582.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001146b.bin
97374573c3a1b765234d34d6759ab8873b6cd447d56adba106e2e125da7197ae
pdf-font-stream PDF embedded font (sfnt) at offset 0x1146B 5312 bytes
font_01_sfnt_off0001265d.bin
27dc665df5bc776d7c17af671e5e49aa400992fa0ecac4f0df91f31e4016e9c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1265D 11164 bytes