Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7222356b3a01263…

MALICIOUS

PDF

78.1 KB Created: 2021-03-06 12:50:42 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: b1b1721709e2e6cc7d5c8d95e41bc1e4 SHA-1: 335af73d766507209be3cd1eb947b5033fe6ac87 SHA-256: c7222356b3a01263eb7775c8df5c5d108397d9f8a3d21ebe68b9d948be888112
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF that contains a large number of external links, many of which are suspicious or unknown. The heuristic PDF_SEO_LINK_FARM indicates a mass of external PDF links, suggesting a link farm or phishing attempt. ClamAV also detected it as Pdf.Phishing.Trojan. The presence of embedded JavaScript, though not fully analyzed, further supports malicious intent, likely to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fokemale.ru/strik?utm_term=will+stocks+continue+to+rise PDF link annotation
    • http://whalesqpa.fun/2892836254l3g95.pdfIn PDF document text
    • http://businessoutsourcing.org/8644507841468v9v.pdfIn PDF document text
    • https://mosejibufo.weebly.com/uploads/1/3/4/4/134437632/bd3b6e405cf22ef.pdfIn PDF document text
    • https://zikegebuner.weebly.com/uploads/1/3/4/8/134856814/sijamadiw-sudidulaboxipo-nemotivo-vedupevaxinotu.pdfIn PDF document text
    • https://tuxuboninivufos.weebly.com/uploads/1/3/4/4/134478209/sidupojirumes.pdfIn PDF document text
    • https://digagewopaloz.weebly.com/uploads/1/3/4/6/134634746/xidagalofelebobexeka.pdfIn PDF document text
    • http://naturebiolog.space/legikusagebomeecvux.pdfIn PDF document text
    • http://antonioit.fun/87587261494u2ryl.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/medaliwifufugel/chota_bheem_tamil_dubbed_episodes.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7f39e708-d2f7-4346-be28-cf380fe32a57/kokidegexideruf.pdfIn PDF document text
    • https://43cb2d18-1589-43a7-b1c5-fe1278e1c76d.filesusr.com/ugd/370b54_21f79c9cb6604698b1e35a328a3c859f.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/webipejonavuv/scotts_speedy_green_3000_settings_for_pelletized_lime.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/68903126-3c51-4674-aa71-a9254a3133ef/are_resistance_bands_good_for_seniors.pdfIn PDF document text
    • https://71a5d838-4e22-4830-8da1-7955ec3365f5.filesusr.com/ugd/f2f43e_47adde1789e34741b5df81c7cdf64bef.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/firigugixujotov/believing_christ_robinson.pdfIn PDF document text
    • https://ae26bae5-b1f3-4fb2-a0ba-5d2f2d23988c.filesusr.com/ugd/aec2ea_82a1c03265cb4effb5d71d339d8ca322.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/satudifin/monitor_cardiaco_touch_es094_-_atrio__bom.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/42807701-8196-414d-b8b4-e25b9111536d/58005566957.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d4151781-dd8b-402f-9320-f33a490851d1/jonoleletisu.pdfIn PDF document text
    • https://s3.amazonaws.com/nalifij/tofuvebokeliwimuki.pdfIn PDF document text
    • https://128fc002-9ed4-4a8f-9a6b-83b43563a9ed.filesusr.com/ugd/6812d7_4235322a6dee46d5b4ee013504901f1f.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/bulolimepol/riddles_with_answers_for_school_assembly.pdfIn PDF document text
    • https://s3.amazonaws.com/wokesabisevo/ibps_rrb_notification_2019_freejobalert.pdfIn PDF document text
    • https://s3.amazonaws.com/dukexajuj/icom_706mk2g_service_manual.pdfIn PDF document text
    • https://s3.amazonaws.com/fewifuwu/jogobekodatumesilewita.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f64d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF64D 4660 bytes
SHA-256: d6414035e41523555c0fe3c8868345e586e69c46c7e67c0283f908aee8a7e243
font_01_sfnt_off00010647.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10647 10828 bytes
SHA-256: 21f2259bd11baa8f114002b97c313827858b78d07730e97dc04aadf5ea697d35