Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1f2899466ed84a0…

MALICIOUS

PDF

76.4 KB Created: 2021-04-07 04:03:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 34d8d4bf662f0cb63a6023e1de7e64d4 SHA-1: 4423c0ea6a50e06aadbcb271a55dc85cf49ba1b5 SHA-256: d1f2899466ed84a01a7c3be63d2c5f1e3d435c1e9fd2e6c8cf34f6465a5e8f93
204 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.007 JavaScript

The PDF contains numerous external links, many of which are part of a link farm, suggesting a phishing or malware distribution attempt. The 'SE_BROWSER_INSTALL_LURE' heuristic indicates the document prompts the user to install a browser extension or update, a common social engineering tactic. The 'ML_NYX_PDF_MALICIOUS' and 'CLAMAV_DETECTION' heuristics confirm its malicious nature, with ClamAV identifying it as 'Pdf.Phishing.Trojan'. No scripts were extracted, but the presence of numerous suspicious URLs and the lure indicate a high likelihood of a phishing or malware delivery attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 7

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=complete+pet+2020+pdf
    • https://cdn.sqhk.co/bavisimupux/hdhifjf/fapefozuremifaxapiturek.pdf
    • https://cdn.sqhk.co/guwewaxa/kFbjdhg/simujataz.pdf
    • https://nerukime.weebly.com/uploads/1/3/1/3/131379394/320970.pdf
    • http://top-agent.ru/425636688716ps2e.pdf
    • http://joy-todays.online/how_do_i_connect_two_bluetooth_headphones_to_my_lg_tveorxo.pdf
    • https://cdn.sqhk.co/bogabixexuja/shcaGjf/38684712897.pdf
    • https://cdn.sqhk.co/siwebove/22Ehajc/50633840480.pdf
    • http://copyright-helps-team.com/46658497622pwjkk.pdf
    • https://cdn.sqhk.co/voravaxa/ihijzgf/popular_english_songs_translated_in_spanish.pdf
    • http://kersita.space/alaska_drivers_license_vision_test_florida6hr1g.pdf
    • https://cdn.sqhk.co/nurijodefa/hdQ9egj/dragon_quest_builders_2_review_gamespot.pdf
    • https://cdn.sqhk.co/naliwanik/hiacqYJ/full_hd_video_player_online.pdf
    • https://sulezesolujoseg.weebly.com/uploads/1/3/1/4/131452841/2bb1d6a.pdf
    • https://cdn.sqhk.co/wujukipako/21gjkjj/bugoleguze.pdf
    • https://cdn.sqhk.co/genibesarizi/eFoykge/6018560422.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/33f5c5f3-6d19-47e9-af33-bbb0bd47d753/modelo_de_contrato_de_arrendamiento_de_vivienda_en_word_sencillo.pdf
    • https://uploads.strikinglycdn.com/files/b261e663-68c8-47f1-892a-6bca50c57984/motorola_t200_talkabout_radio_review.pdf
    • https://uploads.strikinglycdn.com/files/c0ec6f92-79be-477e-a7c3-e45d468edefc/zomomiwigofenubujejonak.pdf
    • http://gizogebinide.rf.gd/cabal_mobile_apk_english_release_date.pdf
    • https://uploads.strikinglycdn.com/files/38c20d3b-b365-4e20-b3be-7721aceee829/conflict_management_styles_animals.pdf
    • http://wetizizokixo.epizy.com/resumen_del_capitulo_11_del_libro_el_arte_de_la_guerra.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb3d.bin
f7f47930056a9bba45018440563c4751ed235b0c3e516b60c5a14863122d5516
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB3D 4884 bytes
font_01_sfnt_off0000fbd0.bin
f1f7bfa81ae1ba68b38023e9db8e3fa59cebcea39563151f05f0d6667e0d48f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xFBD0 12236 bytes