Malicious PDF — malware analysis report

Static analysis result for SHA-256 db708d85b5dd8aba…

MALICIOUS

PDF

76.2 KB Created: 2021-04-02 13:45:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 83594235f18f2e3282d71d86090af52a SHA-1: a97485e8d46d7258f3eabb4f77900067e0c52aca SHA-256: db708d85b5dd8abad258999c1bd8f76db69f2c355104ba1eac55058f7c8e19eb
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a primary link pointing to a site offering cracked software. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. The document body, though heavily corrupted, contains keywords related to software cracking, reinforcing the phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/award?keyword=abbyy+pdf+transformer+3.+0+free+download+with+crack
    • http://twobigs.space/hamari_adhuri_kahani_full_movie_downk0y5q.pdf
    • http://soldonlakewood.com/is_a_mini_split_more_efficient_than_a_window_unit8qcfa.pdf
    • http://matroskin.space/top_games_2019_apkinkrz.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://7211abc3-b26e-437e-abd8-8a8c7ebd4af5.filesusr.com/ugd/0683fb_53e11457e8c84622832ba5cb32a0bfb2.pdf?index=true
    • https://025b4bf0-2906-4f5f-8a0f-6d4b68fc9518.filesusr.com/ugd/148ee2_077e0bfc83c54474af211bf97eb9178e.pdf?index=true
    • https://s3.amazonaws.com/gawabog/vasulasudexe.pdf
    • https://73a1781f-5c9f-4c76-8a11-a8e8c44f336a.filesusr.com/ugd/d9f7b5_022eef10968345278c90a25efadbcb4a.pdf?index=true
    • https://s3.amazonaws.com/bejexe/lonely_planet_guide_perth_australia.pdf
    • https://ba789de2-c385-43ee-b32d-a34c698d1993.filesusr.com/ugd/b7082a_12ec0605149f45f892ecb4e80d09d2af.pdf?index=true
    • https://s3.amazonaws.com/vekodupiwarobi/medilivag.pdf
    • https://8607b5f8-c2b2-49b7-a314-b17bd4efff40.filesusr.com/ugd/d99252_e224ee6b0e404fcb8bf526b8fcc219a8.pdf?index=true
    • https://0306adf0-382e-42f1-903d-71c3961c97f1.filesusr.com/ugd/7ff653_1935c0874d6346b39a2805ec8479d895.pdf?index=true
    • https://s3.amazonaws.com/tubukeganuji/lizokuxewojazewivawolaj.pdf
    • https://e82ff0bd-cb1a-4782-8b92-0a0fb7657660.filesusr.com/ugd/d17951_dda9ea6023fc46b4b911f3eff4169f04.pdf?index=true
    • https://ded05c8b-f0d8-42bc-a64b-daa0b63394ca.filesusr.com/ugd/99afdc_6039ca6ea70f4109857dc6681001b693.pdf?index=true
    • https://s3.amazonaws.com/pujinit/topona.pdf
    • https://9ebe8999-295a-4f11-87dc-c96f3e1b46ff.filesusr.com/ugd/8de238_f6d3546422e942b8b7ebc723006d30c6.pdf?index=true
    • https://s3.amazonaws.com/risisipajole/editorial_plan_template.pdf
    • https://s3.amazonaws.com/lerezazo/tivofefigubuxojifofejo.pdf
    • https://52f9d6e5-2fd5-4906-a030-4d12f703b62a.filesusr.com/ugd/297ecd_2f9be16ccb5f4666ba3b2971f7245244.pdf?index=true
    • https://s3.amazonaws.com/xoferuzu/does_dunkin_donuts_have_keto_friendly_drinks.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e832.bin
21cd3f9ab48a47c2bbe0f21f8ceb685a215a3f59a164411e96b13b09c341ec9e
pdf-font-stream PDF embedded font (sfnt) at offset 0xE832 6120 bytes
font_01_sfnt_off0000fcf3.bin
24c2696f79a709de660e7b862b583fab059e578e767185c2714e0b87cbb00d38
pdf-font-stream PDF embedded font (sfnt) at offset 0xFCF3 11232 bytes