Malicious PDF — malware analysis report

Static analysis result for SHA-256 b922aaa959d32e62…

MALICIOUS

PDF

82.5 KB Created: 2021-03-22 04:05:24 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 07920bd1f8ea9d81b3b322fde7dfb3b6 SHA-1: d8cdb7666c98941a6914bef09d84827fb21b3a1c SHA-256: b922aaa959d32e625dc892bc92603d03187bb0b6090355d527420a29ee9f3aa2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are designed to appear as legitimate search results or document downloads, but lead to malicious domains. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or malware distribution. The embedded links suggest an attempt to redirect the user to a compromised website for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=cask+of+amontillado+escape+room+answers
    • https://cdn.sqhk.co/xagaxubibiz/iihajfj/varobigabudirubamebupogi.pdf
    • https://fegikunula.weebly.com/uploads/1/3/4/4/134482285/jowezuvo_witigijavuli_zirovax.pdf
    • https://fimezerix.weebly.com/uploads/1/3/4/4/134478386/timegijo.pdf
    • https://cdn.sqhk.co/vopupevomate/diigfig/39502465474.pdf
    • http://midosiw.22web.org/oxford_dictionary_download_file.pdf
    • https://doziverilobeku.weebly.com/uploads/1/3/2/6/132695566/239928f71.pdf
    • https://tatidadimu.weebly.com/uploads/1/3/5/3/135383915/2454280.pdf
    • https://cdn.sqhk.co/zenekukera/cgjhfhd/friendship_quotes_in_malayalam_with_images.pdf
    • https://vinofuloro.weebly.com/uploads/1/3/4/8/134850824/7028883.pdf
    • https://keminugugenoxag.weebly.com/uploads/1/3/4/3/134321568/busimegisajusovodiw.pdf
    • https://numeroluxovuz.weebly.com/uploads/1/3/4/7/134733954/1028070.pdf
    • https://buzijivugaza.weebly.com/uploads/1/3/4/7/134709386/9714193.pdf
    • https://lowezikalazana.weebly.com/uploads/1/3/0/9/130969016/besot.pdf
    • https://cdn.sqhk.co/dubikureta/7VhUjhp/42538320885.pdf
    • https://pavibizad.weebly.com/uploads/1/3/0/7/130740264/vurisit-dogupuboxadifib-timowowevaloduz-wiwufiz.pdf
    • https://mofasabopileb.weebly.com/uploads/1/3/4/1/134109330/livug.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/mogedozara/95767766422.pdf
    • https://s3.amazonaws.com/vajefam/corporate_id_card_design_template.pdf
    • https://s3.amazonaws.com/kewuxejikiwe/arijit_singh_song_bada_pachtaoge.pdf
    • http://gawekavadave.epizy.com/adobe_xd_tutorial_espaol.pdf
    • https://s3.amazonaws.com/wulotugadag/25376427486.pdf
    • https://s3.amazonaws.com/remavuj/cd4511bcn_datasheet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e6f5.bin
a606a6dede3b99472d2ac97761204782646b5f75106b48d1abccbe9a99ca9a4c
pdf-font-stream PDF embedded font (sfnt) at offset 0xE6F5 6440 bytes
font_01_sfnt_off0000f6e9.bin
8679e5ea5b8724532d9412139152608d9f01ba30312a0fd805db0a9eabf216db
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6E9 5268 bytes
font_02_sfnt_off000108ce.bin
d9c4753d3998f84e568cb911be4529f19242c68fd7e4f98f73a74f26a3b4f866
pdf-font-stream PDF embedded font (sfnt) at offset 0x108CE 11016 bytes
font_03_sfnt_off00012e23.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x12E23 4324 bytes