Malicious PDF — malware analysis report

Static analysis result for SHA-256 d83a5bdea5ffc561…

MALICIOUS

PDF

77.0 KB Created: 2021-03-24 10:54:50 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-02
MD5: 341249df6027b39c8b1754da277e337e SHA-1: bce9dc44d1f3614f008e308cd0220bc3023b7ff0 SHA-256: d83a5bdea5ffc56155d3650af4ac99752760ac6164239a911a36f4b5babbec9b
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a large number of external links, many of which are SEO-optimized and point to other PDF documents, suggesting a link farm for phishing or malware distribution. The primary URL, https://botokaw.ru/wix?keyword=whirlpool+microwave+wmh31017ab+manual, is presented as a manual but likely leads to malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/wix?keyword=whirlpool+microwave+wmh31017ab+manual PDF link annotation
    • https://cdn.sqhk.co/wojidumezu/chd8MwC/stack_overflow_careers.pdfIn PDF document text
    • https://cdn.sqhk.co/letarezetap/glkiijh/37947139217.pdfIn PDF document text
    • http://figimumagoko.mygamesonline.org/finders_keepers_movie_jim_carrey.pdfIn PDF document text
    • https://cdn.sqhk.co/viwitukaz/jwEjfsq/aasld_hepatocellular_carcinoma_screening_guidelines.pdfIn PDF document text
    • http://zugapuvu.mywebcommunity.org/sennheiser_xs_wireless_headset_mic.pdfIn PDF document text
    • https://cdn.sqhk.co/nuvexajamu/jgO2Oic/geometry_defense_infinite.pdfIn PDF document text
    • http://lukiduxipapep.mywebcommunity.org/bms_controls_and_hvac_systems.pdfIn PDF document text
    • http://mizebojusur.mypressonline.com/66238489042.pdfIn PDF document text
    • https://cdn.sqhk.co/tezakagadol/bgikUjd/fugorivitedaped.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://11ab4cf5-156d-4417-99e9-5039b2a7eb5f.filesusr.com/ugd/82d61e_ac5b64b87a154875a4ada884488bda37.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/fuwenoxuzasila/zazefit.pdfIn PDF document text
    • https://s3.amazonaws.com/divikufifir/pofakavasajuketijod.pdfIn PDF document text
    • https://7095e710-59ac-4d27-8a5a-f3bbcaf65deb.filesusr.com/ugd/418e76_d971251a730a4d8980da176650857fa0.pdf?index=trueIn PDF document text
    • https://s3.amazonaws.com/gasodamuza/larexawavedubipaxugesax.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c961fefb-8daa-48a2-9174-3a131bf79ef0/788516572.pdfIn PDF document text
    • https://s3.amazonaws.com/lewuli/anticoagulante_farmacologia.pdfIn PDF document text
    • https://s3.amazonaws.com/nutanigonu/batch_file_programming_for_loop.pdfIn PDF document text
    • https://s3.amazonaws.com/dosipive/5447093805.pdfIn PDF document text
    • https://s3.amazonaws.com/luworizesupox/identity_theft_report_canada.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4a013da0-8133-42f8-8c6c-bc825bce9d53/tp-link_tl-pa4020pkit_powerline.pdfIn PDF document text
    • https://s3.amazonaws.com/toliwudalamem/72029577809.pdfIn PDF document text
    • https://20128683-61eb-4207-b985-d468b1a81fea.filesusr.com/ugd/0049ca_d849055f7a8a4550b1581fb8ff9d4ff6.pdf?index=trueIn PDF document text
    • http://redifigikutusoj.myartsonline.com/vusuxenowoxugag.pdfIn PDF document text
    • https://s3.amazonaws.com/dobikasukavu/lujakupupaligimofena.pdfIn PDF document text
    • https://s3.amazonaws.com/gezizefefififa/jaxosivepobunawufesuneki.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df31.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDF31 5540 bytes
SHA-256: b779559075b6d5763606e2f81dc69231ba00c7dae446eecb75aa6f87ffa43562
font_01_sfnt_off0000f1ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF1EC 10728 bytes
SHA-256: 984db2abe263b1a36cda0a3f74d65b2c06338c03b1f3bd9d978e98dc38b6d562
font_02_sfnt_off00011634.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11634 4324 bytes
SHA-256: 1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e