Malicious PDF — malware analysis report

Static analysis result for SHA-256 c81f7b6b52956f2d…

MALICIOUS

PDF

87.2 KB Created: 2021-05-10 19:37:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c82d9a63c1081c8061e04e8312c75a00 SHA-1: 58718340bd7608a393a912b2e1f23eb819fdfede SHA-256: c81f7b6b52956f2db9b2344f965124e22207e049e89fb4ede01774a1163ad199
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a technique often used for SEO spam or phishing. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and the ClamAV detection as 'Pdf.Phishing.Trojan' strongly suggests malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the overall structure point towards a phishing or malicious redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=pentair+pool+pump+repair+parts
    • https://cdn.sqhk.co/gederanew/rejinVg/pepper_s_italian_restaurant_lakewood_oh.pdf
    • https://cdn.sqhk.co/sezunofubuzi/Mnbolha/tiktok_tags_for_likes_and_followers.pdf
    • https://cdn.sqhk.co/nupasoxure/Kidjh2i/vetojamonofifilivog.pdf
    • https://potijesidademut.weebly.com/uploads/1/3/4/3/134351663/susitaruxunak.pdf
    • https://cdn-cms.f-static.net/uploads/4501028/normal_605f8709853f3.pdf
    • https://cdn.sqhk.co/xonudutixova/jiajg76/74727570561.pdf
    • https://cdn.sqhk.co/tefozakozup/Jih0QJ7/kuxof.pdf
    • https://cdn.sqhk.co/jelazeneno/hgTTghh/94213899979.pdf
    • https://kozitasulama.weebly.com/uploads/1/3/4/6/134647404/46893e6.pdf
    • https://cdn.sqhk.co/lufezeralon/M3hajes/pocket_watch_tattoo_drawing.pdf
    • https://cdn.sqhk.co/jabisopomuxo/cjelNXI/dokalomoxokow.pdf
    • https://watuxiso.weebly.com/uploads/1/3/2/7/132740831/fewipowexuwus-memen.pdf
    • https://nekazadezi.weebly.com/uploads/1/3/4/6/134662300/vifutadalaz_zakemamelowulev_xereselamanov_wopokaxede.pdf
    • https://pejapuvurexoku.weebly.com/uploads/1/3/1/6/131636728/b1618.pdf
    • https://bamufikike.weebly.com/uploads/1/3/1/6/131606241/xuvoforub_dilukopuv.pdf
    • https://zetodimamewiwek.weebly.com/uploads/1/3/2/3/132302859/8096752.pdf
    • https://sinepakeje.weebly.com/uploads/1/3/4/4/134490574/pusojorifaki.pdf
    • https://cdn-cms.f-static.net/uploads/4420014/normal_602105ce555e4.pdf
    • https://cdn-cms.f-static.net/uploads/4460449/normal_604f687df12f5.pdf
    • https://jizufolikoni.weebly.com/uploads/1/3/4/3/134349493/xitebijun-bojekixuza-kufitodebamala-jifufulu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://wevosowenafa.epizy.com/zopijeguduzadajosoneredob.pdf
    • http://jibizedatamod.epizy.com/komusipajisefotulo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011900.bin
08396247c8937d4d23f14aa78abcfdda7fa9c94003fe7da49e4ebf9701df8836
pdf-font-stream PDF embedded font (sfnt) at offset 0x11900 4968 bytes
font_01_sfnt_off000129c9.bin
e1bf58e8a7a2d3e0fc6a939efc4d2e4414bbe1e585726c8bf52e3211f76ea420
pdf-font-stream PDF embedded font (sfnt) at offset 0x129C9 11196 bytes