Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd88613e15138afb…

MALICIOUS

PDF

75.4 KB Created: 2021-02-23 01:48:11 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-18
MD5: 4d24af22ada81584178fe987c1cd7e3c SHA-1: 96ea2533f3454430e37b49b22b3b44a24a9eb006 SHA-256: bd88613e15138afb9ec0428ac9ea89c452fe93ae5467dc9e0fe0dc53d02f99e1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, indicating a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly suggest malicious intent, specifically identified as a phishing trojan. While no scripts were explicitly extracted, the presence of embedded URLs and the heuristic findings point towards the document's purpose of redirecting users to potentially malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/wix?keyword=truly+tasteless+jokes+pdf PDF link annotation
    • https://bemaxeviliw.weebly.com/uploads/1/3/4/4/134482954/dotekafori-buvezo-pafoweveze-jusixilusa.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4485822/normal_5ff625d6d2e9c.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4471109/normal_5ffa41ef898a8.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4390097/normal_5fdd6e44cc621.pdfIn PDF document text
    • http://damisidituwupo.iblogger.org/design_t_shirt_template_illustrator.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4478125/normal_600128a9c369a.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://dukuzuwikisos.epizy.com/vilorelixopiki.pdfIn PDF document text
    • http://jamosafiseb.rf.gd/dream_league_soccer_classic_hack_apk.pdfIn PDF document text
    • https://s3.amazonaws.com/ganubifirigevi/32720355307.pdfIn PDF document text
    • https://s3.amazonaws.com/nisiwanolom/root_android_without_computer_2018.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb4e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB4E 5228 bytes
SHA-256: 052bb2f7a2873b35065a858f1d02c68ab0cc068ca4bb8f417555ea406e5457b9
font_01_sfnt_off0000fd39.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFD39 10592 bytes
SHA-256: 56f14aea5b09ba676284c78d88bf51043f995c1f46030f962c53a7555a30a46a