Malicious PDF — malware analysis report

Static analysis result for SHA-256 b8fd65a6b692fc40…

MALICIOUS

PDF

80.0 KB Created: 2021-04-06 11:01:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c0636dbee0d451cb4ba0202325993132 SHA-1: 642a47bf0ba4603e2524762c46cb9c6317284624 SHA-256: b8fd65a6b692fc409b08bd46da9ec729a22ad6fe3aa6326f4ddc938da797608b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying it as a PDF link farm designed for SEO. The primary malicious URLs identified are 'https://xezojetit.ru/wix?keyword=intermatic+heavy+duty+outdoor+timer+manual' and 'http://kuzexamipapoxip.medianewsonline.com/41054439476.pdf'. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or distributing further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/wix?keyword=intermatic+heavy+duty+outdoor+timer+manual
    • http://kuzexamipapoxip.medianewsonline.com/41054439476.pdf
    • http://summ-green.fun/gisesegirz7hbo.pdf
    • http://deutschebank-meine.com/zeal_spy_apk_downloadnxgeb.pdf
    • http://bivaxopepukoxi.getenjoyment.net/acordes_de_acordeon_de_botones_en_sol.pdf
    • http://tadefog.medianewsonline.com/33794915102.pdf
    • http://fifamarketbot.com/20052212509mtkzz.pdf
    • http://trastqort.online/estruturas_de_ao_pfeillgf5g.pdf
    • http://duwinijuj.mypressonline.com/bookmark_file_online.pdf
    • http://draiwenstore.online/725896527722v9r8.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://93dbb2ad-f1e8-4c6c-adfd-2ef134399473.filesusr.com/ugd/df4650_b03c4680c8014c91b51cfff8ed484dc7.pdf?index=true
    • https://s3.amazonaws.com/tuxexi/mavatomof.pdf
    • http://suduxegowur.onlinewebshop.net/betaseron_package_insert.pdf
    • https://d0f5cf02-e55f-42e7-ba97-8a4d5a2b8368.filesusr.com/ugd/7f59a0_f1836e294f8843d89d16c2096992d3d6.pdf?index=true
    • https://0c2a99dd-71fd-4a0d-b96f-672cfa785c21.filesusr.com/ugd/515c54_5290dbeb30c048dea51de3a7e5a67c59.pdf?index=true
    • http://zevesijuduma.atwebpages.com/zorba_the_greek_quotes_dance.pdf
    • https://f579be4a-c2ec-451d-94ee-532237c06880.filesusr.com/ugd/9f6a24_1213e1b7d9cb4515aa7f4dda29f858ef.pdf?index=true
    • http://gakilasefit.myartsonline.com/figegurudepegi.pdf
    • https://8d684a1e-4078-49cd-b336-05adf09473b6.filesusr.com/ugd/2b25e8_eb926e7597914002bdafc70caa296e3d.pdf?index=true
    • https://s3.amazonaws.com/xebuvuwov/bibliography_format_for_books_mla.pdf
    • https://95a57b4d-a24c-4412-bd87-88f4f885d252.filesusr.com/ugd/011e4b_56cba6ed33f14199b6b189ff0188241a.pdf?index=true
    • https://a19d597f-2220-41b3-9459-688249e8a20b.filesusr.com/ugd/f19f53_9577bffc2d8e47efbe331a190d73d7e4.pdf?index=true
    • https://6205d428-d5dc-494e-bbc3-e2236f9d811e.filesusr.com/ugd/6885a6_883b83c1ed5f4505828cae0fbd2ea059.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fbca.bin
8195fcd7357bdf5c5a601dd4c6929ce2918e7d49f7d70ecbf706b4032578b997
pdf-font-stream PDF embedded font (sfnt) at offset 0xFBCA 5100 bytes
font_01_sfnt_off00010cfb.bin
c52bc8c1014821f3b87af00abb5e4a37eb67c23d843d6a25bfdab1a5bb631bf4
pdf-font-stream PDF embedded font (sfnt) at offset 0x10CFB 10928 bytes