Malicious PDF — malware analysis report

Static analysis result for SHA-256 d50079bcc3dc60a2…

MALICIOUS

PDF

78.7 KB Created: 2021-04-29 05:05:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: aa8a8118556d8354d686668dfefdd34a SHA-1: 4c2e31702f890b0775300dae5d8838e87dd3bb23 SHA-256: d50079bcc3dc60a25c69119fc479725f8fc04e44d999dc95d687e9e53a03e5f6
186 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to disposable hosting and are used in a link farm. One of the extracted URLs, 'https://bologen.ru/strik?utm_term=what+is+probability+simple+definition', is flagged as unknown reputation, and the ClamAV detection indicates this PDF is a phishing trojan. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/strik?utm_term=what+is+probability+simple+definition PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4381541/normal_5ff4d1416b120.pdfIn PDF document text
    • http://se-mrush.com/walmart_money_card_wont_register3dwev.pdfIn PDF document text
    • http://notdull-eng.online/freak_the_mighty_you_cant_judge_a_book_by_its_cover_quotesiv0ny.pdfIn PDF document text
    • http://dajobod.getenjoyment.net/3702868049.pdfIn PDF document text
    • http://adminhalil.com/ashwini_mudra_yoga_steps_in_tamiltkwc0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4385228/normal_606b41ef17f22.pdfIn PDF document text
    • http://sayseedokg.com/the_taming_of_the_shrew_katherines_final_speech_analysisnybjs.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/305f5b1a-15f1-47d7-a01c-92b921d30a09/bodewakekosajogem.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/47077c64-440a-4a94-aa18-713d555817f0/what_is_the_message_of_the_poem_ozymandias.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5a03ec1d-fce4-4ef1-b19a-d83670a8206f/rich_dad_poor_dad_summary_in_hindi_download_free.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7343393e-c4cd-4394-aa06-af935fb24eec/30241572505.pdfIn PDF document text
    • https://8b8c7005-3af0-45a1-8e5b-a6902caa9335.filesusr.com/ugd/dbd7d9_c492e349a33847788fd83c624c291709.pdf?index=trueIn PDF document text
    • https://a6f18165-9bfd-46c9-8f51-0ab50cd0b687.filesusr.com/ugd/265c7a_2a03872d68e74c66b4d6f2d1918d115f.pdf?index=trueIn PDF document text
    • https://a86a6b26-b473-4b55-b9aa-7628a2bff077.filesusr.com/ugd/4f270c_83d0456249a54d1ebb2b5893cce9537d.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/39f09548-3dbd-4f2b-b2be-bb0886b769f8/xeluxu.pdfIn PDF document text
    • https://22e365c6-0853-42e1-82f8-83473bf9c0bf.filesusr.com/ugd/217d68_5c764ca6460d4b539a088e55d6ace527.pdf?index=trueIn PDF document text
    • https://uploads.strikinglycdn.com/files/6e97d943-665e-4ec6-a77f-62320ed9d6ad/pifasegevu.pdfIn PDF document text
    • http://temodorofeg.atwebpages.com/describing_people_s_appearance_english_exercises.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f3de.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF3DE 5536 bytes
SHA-256: b3303bd2655f51368c0cb8ad535161298287e7f8bdbe3870f096e5b3a33998c8
font_01_sfnt_off00010691.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10691 11224 bytes
SHA-256: 57bc18c4c685f26deb9b7c35781bfd29e9e554ee0f9695cf64eb933c68e50727