Malicious PDF — malware analysis report

Static analysis result for SHA-256 d71f345e0243b8c7…

MALICIOUS

PDF

79.4 KB Created: 2021-04-10 14:55:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2102a32f971a9e9eb752e1c537d41720 SHA-1: 27b269ffc77569e0921ddcd16029abe882603df3 SHA-256: d71f345e0243b8c77f8c18c6f0a99311da0541422f8fc4132b22ee96d9b7c4f6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains a large number of external links, a technique commonly used in SEO link farms and phishing campaigns. The heuristic 'PDF_SEO_LINK_FARM' specifically indicates this behavior, with one of the primary URLs being http://goxafufi.rf.gd/paint_shop_pro_2018_free.pdf. The ML classifier and ClamAV detection strongly suggest malicious intent, likely to redirect users to malicious sites for further exploitation.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/strik?utm_term=totin+chip+requirements+2018
    • https://static.s123-cdn-static.com/uploads/4392862/normal_5ff256a79a40b.pdf
    • https://static.s123-cdn-static.com/uploads/4494147/normal_5fdfc81425e33.pdf
    • https://cdn-cms.f-static.net/uploads/4420039/normal_6018f67b14c17.pdf
    • https://kepuwizetel.weebly.com/uploads/1/3/5/3/135304134/4188833.pdf
    • http://najetaxu.mygamesonline.org/27278307779.pdf
    • https://gikesusemu.weebly.com/uploads/1/3/4/7/134775173/6385235.pdf
    • https://satizivuzaked.weebly.com/uploads/1/3/4/3/134383512/332311dd7bab9f.pdf
    • http://tulomodev.getenjoyment.net/does_light_relief_work_for_arthritis.pdf
    • https://cdn-cms.f-static.net/uploads/4377408/normal_605dc399045bc.pdf
    • https://cdn-cms.f-static.net/uploads/4529977/normal_60209b92ba814.pdf
    • https://cdn-cms.f-static.net/uploads/4459929/normal_601ae89890238.pdf
    • https://cdn-cms.f-static.net/uploads/4381546/normal_603271a5bf283.pdf
    • https://cdn-cms.f-static.net/uploads/4387218/normal_600ec173d87dc.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://goxafufi.rf.gd/paint_shop_pro_2018_free.pdf
    • http://vofogidazok.epizy.com/46934954080.pdf
    • http://volitig.rf.gd/beaconsfield_school_ofsted_report.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ea21.bin
80b73896f05bcaf235a5dcc357372f984b4a2f3a208f92d5da1f30802e1ed5f6
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA21 5408 bytes
font_01_sfnt_off0000fc5e.bin
2866084afe551dc460b7f543ed3eed08516f8714cc408c65fb7781d48a3bc223
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC5E 11188 bytes
font_02_sfnt_off0001227c.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x1227C 4324 bytes