Malicious PDF — malware analysis report

Static analysis result for SHA-256 d458f957fb748157…

MALICIOUS

PDF

78.2 KB Created: 2021-04-06 03:46:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a3a20e2efcd68f613ed421224f33f2da SHA-1: da08228c4b30fb5346cd10f2e08236ce8b745fd3 SHA-256: d458f957fb7481573e8d423fe2f5459c98ac5c41177ba3512b2b4050d40ee06f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying a link farm designed to direct users to other PDF documents. The primary URL, 'https://bologen.ru/strik?utm_term=iphone+5c+battery+connector+pinout', suggests a lure related to iPhone parts, likely for phishing or scam purposes. ClamAV detection and ML classification further support its malicious nature, indicating it's a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=iphone+5c+battery+connector+pinout
    • https://nojabepeteguki.weebly.com/uploads/1/3/4/6/134669956/biviwisipowuti.pdf
    • https://cdn-cms.f-static.net/uploads/4391605/normal_606a3249f4204.pdf
    • https://cdn-cms.f-static.net/uploads/4372707/normal_6025ca8139a91.pdf
    • https://bujozimadepaxed.weebly.com/uploads/1/3/4/6/134615651/subem.pdf
    • https://nubipudovolena.weebly.com/uploads/1/3/4/0/134012318/darawimeratoritaw.pdf
    • http://mosomupusafebin.medianewsonline.com/74310560049.pdf
    • https://cdn-cms.f-static.net/uploads/4412778/normal_604816e4476d7.pdf
    • https://cdn-cms.f-static.net/uploads/4500183/normal_6060f80c0710d.pdf
    • https://cdn-cms.f-static.net/uploads/4391308/normal_6060d5163c725.pdf
    • https://pelifofenap.weebly.com/uploads/1/3/3/9/133997555/02ec083e.pdf
    • https://static.s123-cdn-static.com/uploads/4490252/normal_5fce146d6855b.pdf
    • https://cdn-cms.f-static.net/uploads/4419818/normal_60356b482632c.pdf
    • https://buzijivugaza.weebly.com/uploads/1/3/4/7/134709386/1485343.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/b708ce23-3715-4fb1-bdfc-2475bbd9df40/how_to_turn_on_fagor_oven.pdf
    • https://uploads.strikinglycdn.com/files/b0be78f9-a28a-44ec-84cf-6c8871d45575/8538150641.pdf
    • https://uploads.strikinglycdn.com/files/122bb1da-2880-450f-aca9-d1c5650cac34/nenomegevem.pdf
    • https://uploads.strikinglycdn.com/files/52ed31ab-344f-4d53-9fde-43eb63fe4f9f/jifizoniwivu.pdf
    • https://uploads.strikinglycdn.com/files/6f5ce184-30bb-47b4-948f-b778d3fd6d08/what_are_the_different_principles_of_design_in_art.pdf
    • https://uploads.strikinglycdn.com/files/ad474fdc-2427-4ace-908f-f90c9b5d32de/quran_in_english_and_arabic_app.pdf
    • http://tobidogajetu.onlinewebshop.net/animator_s_survival_kit_online.pdf
    • https://uploads.strikinglycdn.com/files/ae345242-2dc3-46e5-b03a-fc9823cedb1a/femujerixupuropadaxilele.pdf
    • https://uploads.strikinglycdn.com/files/10e6b3bd-dd75-4d03-9cca-1d62b2c4d793/konosuba_light_novel_volume_16_release_date.pdf
    • https://uploads.strikinglycdn.com/files/9b7c4647-5f01-47f5-a706-9b212e87c054/what_are_the_5_bodies_of_water.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3ad.bin
573404feb03d4504cbb5c038c25c822b2eedb6f09421b1dc1426273bf0ca86df
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3AD 5116 bytes
font_01_sfnt_off0001051a.bin
ab9c6b15b7dc74d64d7e12a087767def22b607a6b8dc6c79ed7961bb5368dee8
pdf-font-stream PDF embedded font (sfnt) at offset 0x1051A 11304 bytes