Malicious PDF — malware analysis report

Static analysis result for SHA-256 d396e3e63b5d8956…

MALICIOUS

PDF

82.7 KB Created: 2021-03-21 05:47:25 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ae302ba5be0ab7af6e123ca02d820033 SHA-1: 2bcfced4d5fa5862a1b1ed06793a195b9400b9c6 SHA-256: d396e3e63b5d89569a48bbd794d6d563c7e2f79e698073b1d8bc9458f7e934da
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, a technique often used for SEO manipulation or to direct users to malicious sites. ClamAV and ML classifiers strongly indicate malicious intent, specifically flagging it as a phishing trojan. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/strik?utm_term=how+to+put+together+the+gazelle+edge
    • http://lowufadit.scienceontheweb.net/biological_classification_ncert.pdf
    • https://cdn.sqhk.co/kuretunaba/6hjhgig/94126082447.pdf
    • https://cdn.sqhk.co/pesasotiro/QjiEHie/warships_games_for_android.pdf
    • https://cdn.sqhk.co/kubasovusi/MhbhhSb/police_drift_racing_mod_apk_download.pdf
    • https://balebapu.weebly.com/uploads/1/3/5/3/135322653/votukux.pdf
    • https://rajomiluti.weebly.com/uploads/1/3/2/6/132682989/vutafilabigu.pdf
    • https://fufefofixikulo.weebly.com/uploads/1/3/1/1/131163927/494e1d.pdf
    • http://zujewubowufonug.scienceontheweb.net/xemuz.pdf
    • http://dewisazovuvoxi.mywebcommunity.org/how_to_save_cisco_config.pdf
    • https://favimorujupufu.weebly.com/uploads/1/3/2/7/132710565/6307728.pdf
    • https://cdn.sqhk.co/sazipuvaxiv/hhbFSjj/candy_kush_grow_report.pdf
    • https://movireralu.weebly.com/uploads/1/3/4/8/134879142/magigigozebo_fexenimowad.pdf
    • http://tixesikixux.mygamesonline.org/nisazozijemidim.pdf
    • https://xizexinapak.weebly.com/uploads/1/3/4/3/134359948/barusizi.pdf
    • https://zorivaleguzovul.weebly.com/uploads/1/3/4/5/134596353/radak-vawovukudo.pdf
    • https://cdn.sqhk.co/sadebupunen/jgihsr0/45769042392.pdf
    • https://fosijegaden.weebly.com/uploads/1/3/4/8/134868146/xekagojuxezebarizuru.pdf
    • http://puvepum.getenjoyment.net/68206285959.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ef97e90d-a742-40d5-9807-e2d5a6b2038e/gender_is_burning_questions_of_appropriation_and_subversion_summary.pdf
    • https://uploads.strikinglycdn.com/files/3c4ec765-5ae8-4927-89de-8d142741323f/65340707596.pdf
    • http://taguloxutenafol.myartsonline.com/how_much_should_a_screenwriter_get_paid.pdf
    • https://uploads.strikinglycdn.com/files/62116eb3-fed4-41fa-b78d-45ca4197770d/minecraft_windows_10_account_free_2020.pdf
    • https://uploads.strikinglycdn.com/files/3008df5e-fc77-47ad-8d98-b926aaad5d61/how_to_use_a_wood_stove_to_heat_your_house.pdf
    • https://uploads.strikinglycdn.com/files/380ee345-9e75-4654-a999-3386cd5fd903/kamiwulipugoliwi.pdf
    • http://kepofif.onlinewebshop.net/89537619062.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000106a2.bin
8b7816a5c0a38862c3acb6a4659afe5d1b4bfc57a06a752c4657f22d3642fb09
pdf-font-stream PDF embedded font (sfnt) at offset 0x106A2 5144 bytes
font_01_sfnt_off00011836.bin
ea3ae7b7ccf569f885509b688c3973500b7c71f62195378ae1988079542e3a06
pdf-font-stream PDF embedded font (sfnt) at offset 0x11836 10936 bytes