Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfe841aa6e7acf42…

MALICIOUS

PDF

89.5 KB Created: 2021-03-24 04:23:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 17598a03cfd4b523057d6f383e803d22 SHA-1: d30eea4f5d0226499bb683c73ad4a885fbaa5959 SHA-256: cfe841aa6e7acf4284b252e10b181393d7cd4a8e135a44e3cfa909988a22687d
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, a common tactic for SEO poisoning and phishing. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of links, and the 'ML_NYX_PDF_MALICIOUS' and 'CLAMAV_DETECTION' heuristics strongly suggest malicious intent. The embedded URLs point to domains commonly associated with malicious activity, such as 'leonvi.ru' and 'internet-babki.ru'.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=dr.+collins+pcat+self-study+guide+download
    • http://internet-babki.ru/how_to_do_a_double_crochet_for_beginnerscagb9.pdf
    • http://likedizar.medianewsonline.com/asia_political_map_download.pdf
    • http://rowowesofazov.medianewsonline.com/zofuluzigasoku.pdf
    • http://hytri.com/26733456975cye87.pdf
    • http://xagakojitogiva.getenjoyment.net/66632811980.pdf
    • http://tikopariwoxa.mygamesonline.org/napegeterovofemuxasodo.pdf
    • http://amsidgi.xyz/nordyne_furnace_troubleshooting_codes0wglt.pdf
    • http://bodaweziwov.mypressonline.com/percy_jackson_sea_of_monsters_villains_wiki.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://9005a25f-7293-4a73-bb0f-bc58e8c16807.filesusr.com/ugd/e3834b_19f5f39828344dbaaf2eb59c31af1084.pdf?index=true
    • https://uploads.strikinglycdn.com/files/be273f66-3195-48f4-91e9-68be2895ae16/libro_el_juego_del_angel_completo.pdf
    • https://uploads.strikinglycdn.com/files/cdc5c458-3145-46f3-92a5-829f24fdafe4/61778117194.pdf
    • https://uploads.strikinglycdn.com/files/6756aba1-33b7-4903-8e03-527690f5a4b4/how_to_deal_with_a_child_with_adhd_and_odd.pdf
    • http://bigamutalunu.atwebpages.com/rofafisafug.pdf
    • https://uploads.strikinglycdn.com/files/cd48beea-0918-4ab6-9277-58db15de4e36/gejafop.pdf
    • https://9abff256-b119-4e75-a612-dfc075f5428e.filesusr.com/ugd/c73517_b3066ba2a9af45fc9d3b4d9c98b7e22b.pdf?index=true
    • http://legokejapo.atwebpages.com/how_do_i_return_to_sender_australia_post.pdf
    • https://e05653fc-386e-4c8b-889d-738aee72c63e.filesusr.com/ugd/62421a_6d17c8c2d24b4248838d0a256e3bf3c0.pdf?index=true
    • https://87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com/ugd/f9d4cd_e0741b9442694a1b892a3cf8cdc82370.pdf?index=true
    • https://s3.amazonaws.com/satuja/what_does_historia_mean_latin.pdf
    • https://s3.amazonaws.com/dowavelaxam/stihl_ms180_parts_manual.pdf
    • https://uploads.strikinglycdn.com/files/6b0702aa-25e4-437b-8688-0f93a851a7b3/jurunakoraverimom.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011d59.bin
c6bac62697a42d54f31afd0f4545a4f104c71d426599d8b8087a255f3c2adb61
pdf-font-stream PDF embedded font (sfnt) at offset 0x11D59 5580 bytes
font_01_sfnt_off00013098.bin
875f86523bd69d770b541c76210de03e721f945154664f093710b3156fc66331
pdf-font-stream PDF embedded font (sfnt) at offset 0x13098 12216 bytes