Malicious PDF — malware analysis report

Static analysis result for SHA-256 c63f274bcaf25540…

MALICIOUS

PDF

81.9 KB Created: 2021-03-24 20:10:13 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: af30fc08c9304f686b2b02868bf74b3a SHA-1: 8d203d04e9e6bf67b4cb91b2c540a89a7622402a SHA-256: c63f274bcaf2554005fc5892865d8ca0c5e127b8048ad6e075647b5fe1ede056
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one pointing to a suspicious URL on 'jumiwimov.ru'. ClamAV and ML classifiers identified this PDF as malicious, specifically a phishing trojan. The heuristic 'PDF_SEO_LINK_FARM' indicates a deliberate attempt to create a link farm, suggesting a malicious intent to direct users to potentially harmful content or downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/strik?utm_term=meade+etx+125ec+price
    • https://static.s123-cdn-static.com/uploads/4389366/normal_5ff4cc8c2955e.pdf
    • https://cdn-cms.f-static.net/uploads/4423189/normal_602f6d96b7459.pdf
    • https://cdn-cms.f-static.net/uploads/4455180/normal_601d53dc6158e.pdf
    • https://cdn-cms.f-static.net/uploads/4375704/normal_6041410dd7eeb.pdf
    • https://static.s123-cdn-static.com/uploads/4452152/normal_5ffa22b7dc2c8.pdf
    • https://cdn-cms.f-static.net/uploads/4382186/normal_60449418e72db.pdf
    • https://static.s123-cdn-static.com/uploads/4370052/normal_5fe41cec2f846.pdf
    • https://static.s123-cdn-static.com/uploads/4378170/normal_5fcbec2c86882.pdf
    • https://cdn-cms.f-static.net/uploads/4401703/normal_6045fee71aa45.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/acd92ebd-cee2-4172-959c-44cb09ad3fa0/who_is_on_the_cover_of_the_sports_illustrated_swimsuit_issue.pdf
    • https://uploads.strikinglycdn.com/files/b517ab42-4269-4dc3-a514-e7aa22e52237/ledevixuloferozil.pdf
    • https://uploads.strikinglycdn.com/files/99623103-f139-4ad1-9e94-8b55a2cdda9b/krk_rokit_5_g2_tweeter.pdf
    • https://fc06435f-e709-4c80-b59d-96fa470c1a13.filesusr.com/ugd/bdc04d_2491206bad984403a49bd56eed2e6da0.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a9a79027-34f7-4511-b183-efac0190671b/gudazevowinekusikimexo.pdf
    • https://uploads.strikinglycdn.com/files/9d9e84fa-b60f-40ae-a68c-1175b573b325/teenage_mutant_ninja_turtles_tournament_fighters_nes_game_genie_codes.pdf
    • https://24a70dd4-b549-4b9e-9c0a-6eea45ab85ad.filesusr.com/ugd/ab0c63_d9634b24f6884abf98cf93258d28f7b7.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d9454e30-3350-4d7b-a2f6-3beac96277bf/bavotasinazejasulo.pdf
    • https://5ac9d038-517d-4536-97f6-676423289421.filesusr.com/ugd/b444d4_ea499a40258f49b4afc34a2e1b2cebcd.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f443.bin
8d2e660e088b8b21de5b2a7d00891fd9a37c95b6ab218c0c5a796d5ee179def0
pdf-font-stream PDF embedded font (sfnt) at offset 0xF443 4808 bytes
font_01_sfnt_off000104b8.bin
bbc83287da1d224bac50e3a0ff64dddf37c10776348b1a2f1a06a46b1e5f282b
pdf-font-stream PDF embedded font (sfnt) at offset 0x104B8 11840 bytes
font_02_sfnt_off00012c8d.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x12C8D 4324 bytes