Malicious PDF — malware analysis report

Static analysis result for SHA-256 bab0d30d5d1aadb6…

MALICIOUS

PDF

83.4 KB Created: 2021-03-17 21:17:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ba1be27d220c54343b5d3ef979c07963 SHA-1: 2814811b80b98a611c9c86c8f2e2f1645d172988 SHA-256: bab0d30d5d1aadb649a2e6e2acddd3a1b5892d2a2580f6d0f6d0696c64de8532
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to benign-looking PDF files, but one key URL, https://mezovuduw.ru/award?keyword=alberto+moravia+agostino+pdf, is flagged as suspicious. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. No scripts were extracted, but the PDF structure itself is used to host numerous links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/award?keyword=alberto+moravia+agostino+pdf
    • https://cdn.sqhk.co/wutakuvi/dekUCgf/84260350881.pdf
    • https://gewafikawesi.weebly.com/uploads/1/3/4/0/134016732/f1bc9.pdf
    • http://libralab.digital/bexadikaparenefwtl8n.pdf
    • https://radobejaka.weebly.com/uploads/1/3/5/4/135400195/rumevonefojum-zifawewanivij-waxibosuxobol-reduxe.pdf
    • http://gakmancreatures.ru/domifuvowitiliti8excw.pdf
    • https://cdn.sqhk.co/togokitaz/QUhijaR/infinity_train_chrome_car_cast.pdf
    • http://yourbigdick.space/godzilla_defense_force_kaiju_dungeonfs6nw.pdf
    • http://ximilakuxulo.iblogger.org/tuwufaxoxakojewibuw.pdf
    • http://tcerkovniekupola.space/alpine_mrv-m500_review5i69c.pdf
    • https://cdn.sqhk.co/zalenelavup/f5wjjyw/my_talking_pet_promo_code.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/1caedd2d-6f40-4d15-b38d-c6d34621c801/descargar_libro_fisica_universitaria_sears_zemansky_volumen_1_edicion_13.pdf
    • https://uploads.strikinglycdn.com/files/260a0776-d504-4f9f-9c9f-0842076d55a5/52136015067.pdf
    • https://uploads.strikinglycdn.com/files/65e31464-e6a4-4d1c-b197-c5292a6a66e1/katuzusevo.pdf
    • https://uploads.strikinglycdn.com/files/7540e680-192a-43f1-8480-cd744c2a16d3/cdigo_ascii_signo_de_admiracion_apertura.pdf
    • https://uploads.strikinglycdn.com/files/45e46f36-92b3-48d9-bf95-68d0530b7f0c/dbt_one_mindfully_exercises.pdf
    • https://uploads.strikinglycdn.com/files/712780d9-9333-459a-9d5c-962743495bc7/real_book_bb_sixth_edition.pdf
    • https://uploads.strikinglycdn.com/files/13d9e38a-aaca-46b8-a437-b179cba87749/masetezakevegewosexadeva.pdf
    • https://uploads.strikinglycdn.com/files/32cf1877-6864-4ce5-8ddb-e12c617a3eba/25488994186.pdf
    • http://nijibibikij.rf.gd/how_many_words_is_harry_potter_book_1.pdf
    • https://uploads.strikinglycdn.com/files/aad7f90a-8c42-4fca-b12e-0c385f869fc4/8645093362.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f98e.bin
f03a7d88bc6aabf9681c54b789951bb9d9f7c859c7f0cf74385f5372c9a01b4e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF98E 5336 bytes
font_01_sfnt_off00010b95.bin
176c87438611bb247d586a7c2e02a18af81bb9f0bb187920e5c11e32305875b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B95 11116 bytes
font_02_sfnt_off00013102.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x13102 4324 bytes