Malicious PDF — malware analysis report

Static analysis result for SHA-256 c634d721481f8882…

MALICIOUS

PDF

68.0 KB Created: 2021-02-27 12:48:32 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c574b02e9cd932e9b43476eb18c17090 SHA-1: 18a9d4d1843058dd24e6776494ed076791656df7 SHA-256: c634d721481f88821fc0e04f4383ba21a7c5c6a200c03021f0e119faf4eff499
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for PDF_SEO_LINK_FARM, indicating it hosts numerous external links, with one pointing to 'https://xezojetit.ru/123?utm_term=the+social+contract+rousseau+audiobook'. This suggests a phishing or malware distribution attempt. The ML classifier and ClamAV detection further support its malicious nature. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a malicious lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/123?utm_term=the+social+contract+rousseau+audiobook
    • https://cdn.sqhk.co/pabilere/geJTvkh/22273593709.pdf
    • https://zexajupa.weebly.com/uploads/1/3/4/6/134692079/ad5dab.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://s3.amazonaws.com/jirebonudur/video_editor_app_for_mobile_apkpure.pdf
    • https://s3.amazonaws.com/dinisemowoge/gizefutejemubukujoleto.pdf
    • https://s3.amazonaws.com/xabalaru/data_mining_techniques.pdf
    • https://s3.amazonaws.com/ribowexulo/windows_10_themes_pc.pdf
    • https://s3.amazonaws.com/xulepiwa/75671402375.pdf
    • https://s3.amazonaws.com/rubidokezive/80152590084.pdf
    • https://s3.amazonaws.com/fosawef/free_keto_diet_cookbook.pdf
    • https://s3.amazonaws.com/zunaporam/78744515188.pdf
    • https://s3.amazonaws.com/loxopudizus/bounty_hunter_korean_movie_english_sub.pdf
    • https://s3.amazonaws.com/wopari/bosch_serie_4_instruction_manual.pdf
    • https://s3.amazonaws.com/fosalizuzu/singham_returns_full_movie.pdf
    • https://s3.amazonaws.com/zevutebulaworel/busakovamudi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c37d.bin
0a9263d555b346c096a5955fdcfdde52325ea61ab8f67be42151076f4c7d8ca5
pdf-font-stream PDF embedded font (sfnt) at offset 0xC37D 5180 bytes
font_01_sfnt_off0000d50e.bin
825942d77b543605ed8fb54a4a38b1ad9b086e87b0c3745e6d202622fba4b266
pdf-font-stream PDF embedded font (sfnt) at offset 0xD50E 9780 bytes
font_02_sfnt_off0000f6cb.bin
e23608f441591f32bce7e723b916f1c6e13c90ed4c5bc5643033112dd0abb488
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6CB 2908 bytes