Malicious PDF — malware analysis report

Static analysis result for SHA-256 b887d8725b75445b…

MALICIOUS

PDF

81.5 KB Created: 2021-03-07 01:01:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2447d36457ddffd955933b67ae5e7caf SHA-1: 774cfdf7428fafb6821b60b76806e05fae928bf7 SHA-256: b887d8725b75445b1c42ac561f9d431a7cd3b76a69c1c68a13c01e001cc6939f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as a phishing trojan. The PDF contains a large number of external links, many of which point to unknown or potentially malicious domains, suggesting a link farm or phishing campaign. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic indicate an attempt to redirect users to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pelibifir.ru/strik?utm_term=2010+sports+illustrated+swimsuit+cover+model
    • http://oneitstore.info/payday_2_god_mode_mody6he1.pdf
    • https://wonikisemuk.weebly.com/uploads/1/3/4/9/134902350/0da2de7a3049c83.pdf
    • https://cdn-cms.f-static.net/uploads/4470679/normal_601eb68f8710e.pdf
    • https://cdn-cms.f-static.net/uploads/4417530/normal_5fdac58d32bfc.pdf
    • https://runufegoxow.weebly.com/uploads/1/3/5/3/135347372/tononufodize.pdf
    • https://duzuvopewawufos.weebly.com/uploads/1/3/4/4/134491429/xonerusu.pdf
    • https://dafufiwe.weebly.com/uploads/1/3/4/3/134368649/fedipemakepig.pdf
    • http://nutristrike-shop.ru/fnaf_world_unblocked_gameseulfy.pdf
    • https://static.s123-cdn-static.com/uploads/4464732/normal_5ffdfd4261e4f.pdf
    • https://xogegexisupu.weebly.com/uploads/1/3/4/3/134319275/91f78e22.pdf
    • https://cdn-cms.f-static.net/uploads/4489599/normal_602ce2a9b00fb.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/perurulexi/vsco_full_pack_premium_apk.pdf
    • https://uploads.strikinglycdn.com/files/2dc1ec0f-2bb2-400c-ab8d-f96308bc31d3/englander_pellet_stove_manual_55-shp10.pdf
    • https://uploads.strikinglycdn.com/files/4c56da92-0aae-4904-a17e-0dae08fa5d7f/turowerubosonotajojuseno.pdf
    • https://uploads.strikinglycdn.com/files/0179589c-e349-4a80-b59d-3cbd9f1a5b74/what_degree_do_you_need_to_be_a_storyboard_artist.pdf
    • https://s3.amazonaws.com/tutapaxi/baby_groot_dancing_guardians_of_the_galaxy_1_song.pdf
    • https://s3.amazonaws.com/warapagefasovi/girededobuwukevun.pdf
    • https://uploads.strikinglycdn.com/files/9d94dc1e-3394-4607-a01b-582cc2f4ece7/sat_writing_practice_prompts.pdf
    • https://uploads.strikinglycdn.com/files/98a26e3c-64cc-48a5-a27f-406456232fc1/44137361916.pdf
    • https://uploads.strikinglycdn.com/files/76d28616-15e8-4ff5-a768-764e7f38c71f/text_to_image_converter_ai.pdf
    • https://s3.amazonaws.com/rubidokezive/39728163396.pdf
    • https://uploads.strikinglycdn.com/files/5df0751a-9c1a-4b67-9c22-2aa0f2a79902/what_is_the_easiest_way_to_learn_medical_terminology.pdf
    • https://s3.amazonaws.com/fusopoxipo/zovibibufujeguvafagusig.pdf
    • https://uploads.strikinglycdn.com/files/97404d3e-dfa1-4677-ae98-885a62efacdd/dulajalelabawewewifinad.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fe60.bin
b1219fa94595b31d36956d552b7b8c90e5c3778d8b337a62d6a0d77a25625973
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE60 5604 bytes
font_01_sfnt_off00011171.bin
3e355af77b19e7a2c649936042e3992602f37a83d1e7897f3950b924801df8a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x11171 11376 bytes