Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba1f1d88bb5bb807…

MALICIOUS

PDF

78.4 KB Created: 2021-03-29 21:30:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d1685341f04b6965e7ce37efb9f832fd SHA-1: 38a1a1a2b519d8dc142691250f12e2662e323fa2 SHA-256: ba1f1d88bb5bb807e947d1ed39a937544a5f3314e690e91ec884ac9a093448b9
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious phishing content. It contains numerous external links, with one specifically pointing to a URL designed to appear as a free warranty deed, likely a lure for users. The presence of many external links suggests a link farm or a distribution point for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=free+texas+warranty+deed+pdf
    • http://guitar.su/64558645161tn1si.pdf
    • https://toxafowusolele.weebly.com/uploads/1/3/2/8/132815148/vexujotub.pdf
    • https://rapinawenag.weebly.com/uploads/1/3/0/9/130969945/c0cfbca.pdf
    • http://baffer-shop.space/2020_mastercraft_xstar_top_speedzky3b.pdf
    • https://nibuwoxemunovox.weebly.com/uploads/1/3/4/7/134714338/gefovufibosapo.pdf
    • http://hightrade.club/getabirikarojegeeb7l.pdf
    • http://ing-jobs-opportunities.com/lunumarovadolekixa4bg.pdf
    • http://mysteps.online/what_does_slant_rhyme_mean_in_poetryx7nkp.pdf
    • https://linabodaku.weebly.com/uploads/1/3/1/1/131164293/vubositomozaz-zatajejagubidol-metudeb-zixakibeluvo.pdf
    • http://tumbochka.space/rs_aggarwal_quantitative_aptitude_download1lxry.pdf
    • http://gazzsheff.xyz/sixozixisiwelevafowan3gd.pdf
    • https://tuzisufuga.weebly.com/uploads/1/3/4/4/134458332/ginujoregedebopekiw.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/zuxime/numujapilulutolaxuxo.pdf
    • https://4c8cc264-4606-483b-a6fd-3ab48ba5c15a.filesusr.com/ugd/c626f4_a07f9ff4328d44b096c28f5a272a8d6d.pdf?index=true
    • https://e0f910ba-f4aa-4d6b-87f6-24d78cda99ab.filesusr.com/ugd/cc15ef_48d82a527f6248a481f907956cbd4884.pdf?index=true
    • https://c809e8a6-5bdf-489d-8d8c-df4e4638a115.filesusr.com/ugd/45a296_755e8a7aadc54ba4a8f90c16993012c3.pdf?index=true
    • https://dc5ca969-d333-4582-9879-b719aca70d73.filesusr.com/ugd/760c43_454d0d1e7a734edc8533b1f171adcba1.pdf?index=true
    • https://s3.amazonaws.com/sazomo/comcast_tv_app.pdf
    • https://s3.amazonaws.com/zalisujezajaje/riwuduwaxemewutivesaz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f455.bin
ab1765f0dc4f91b70322884d54a0f53f15b5e4a1b65ae412d748e6389ed84bbb
pdf-font-stream PDF embedded font (sfnt) at offset 0xF455 5220 bytes
font_01_sfnt_off00010645.bin
99a4f009932cfd87ce398fc5b3c0294ae7d4720f6ff3b4929be7551d357dba6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10645 11360 bytes