Malicious PDF — malware analysis report

Static analysis result for SHA-256 ccdb72af9b22e0fe…

MALICIOUS

PDF

83.7 KB Created: 2021-02-09 23:55:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-03
MD5: 9ae601f9cbafae632c47e2984e8f6c2f SHA-1: 978cf353685c3fa4d5d118c7c8ba73dd8bf95b82 SHA-256: ccdb72af9b22e0fefed585aa06a693f95ba15c09c06a68be3f24819b2e7af4f8
204 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link T1059.007 JavaScript

This PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection and an ML classifier. It contains a large number of external links, many of which point to PDF files, suggesting a link farm or redirection to malicious content. The presence of a remote-support tool lure and a download button further indicates a phishing or social engineering attempt. No scripts were extracted, but the PDF structure and numerous external links strongly suggest it is designed to lead the user to download or interact with malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 7

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://seumenha.ru/aws?utm_term=rupinder+gandhi+2015+full+movie++480p PDF link annotation
    • https://cdn.sqhk.co/doxurozupu/Sja67qH/30196249011.pdfIn PDF document text
    • https://cdn.sqhk.co/bobavijiwoba/baWR7gf/formula_1_manager_game.pdfIn PDF document text
    • https://cdn.sqhk.co/wirumedaba/dhcz9ie/botuzipowun.pdfIn PDF document text
    • https://cdn.sqhk.co/zevukodixu/eic3z2o/wabepeware.pdfIn PDF document text
    • https://cdn.sqhk.co/xasexuwosul/jijhjim/92857599405.pdfIn PDF document text
    • https://cdn.sqhk.co/tigixexaxi/Tuihhh5/diversified_machine_systems.pdfIn PDF document text
    • https://cdn.sqhk.co/tarolaser/OFTig5l/ditikugoripijorum.pdfIn PDF document text
    • https://cdn.sqhk.co/tinolaseja/Mggjb9f/xewafujonix.pdfIn PDF document text
    • http://dubiniba.iblogger.org/nixufobodizomufaja.pdfIn PDF document text
    • https://cdn.sqhk.co/xelalizogim/AgenBib/kobilobakivur.pdfIn PDF document text
    • https://cdn.sqhk.co/jaselavujuwi/P4gewjc/pumpkin_carving_near_me.pdfIn PDF document text
    • https://sodapovi.weebly.com/uploads/1/3/4/4/134494820/9815003.pdfIn PDF document text
    • https://nanuvofekoredam.weebly.com/uploads/1/3/5/3/135385966/9350960.pdfIn PDF document text
    • https://cdn.sqhk.co/nalujujoso/ic08hfy/iphone_x_notification_ringtone_mp3_download.pdfIn PDF document text
    • https://cdn.sqhk.co/fujonexa/iduL2HE/arcade1up_asteroids_deluxe.pdfIn PDF document text
    • https://cdn.sqhk.co/juduxijumijo/hghB6jc/konatorit.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://scripts.sil.orgThisIn PDF document text
    • http://www.fontrix.comhttp://www.nhncorp.comIn PDF document text
    • http://remupuxuwuved.rf.gd/cartoons_2018_movies.pdfIn PDF document text
    • http://dumudolaba.epizy.com/jujalerizegewizulap.pdfIn PDF document text
    • http://kirigawegugava.epizy.com/liboz.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://scripts.sil.org/In PDF document text
    • http://scripts.sil.org/OFLAbyssinicaIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d300.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD300 6076 bytes
SHA-256: 61d80b7b49f4b4e8c313adfd5ee9fc810d4f9179edbfd454364a63c2ec1bd819
font_01_sfnt_off0000e798.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE798 20968 bytes
SHA-256: 87985804ebf98b1030980f20b4e39595e1aa76caccafc3e7d64f2ca02509db1c
font_02_sfnt_off000107c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x107C9 2276 bytes
SHA-256: 5e0676e134781f2a21c06a0d045eebc95ad2f72f5ed7fc876ffdcead7ccbe471
font_03_sfnt_off00011193.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11193 11168 bytes
SHA-256: 12edde8fa0125b88e44bc350f387485920e018bcf31e00ef5d35d35bc5051f13
font_04_sfnt_off000137ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x137AE 2056 bytes
SHA-256: e5f30af547b55dfbbae63869c45e93d04e829a64999393572a2275da8290585e