Malicious PDF — malware analysis report

Static analysis result for SHA-256 dee21d65b2b6129b…

MALICIOUS

PDF

72.0 KB Created: 2021-05-28 22:29:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 300f6eeaff5f49d26f54e67b079db683 SHA-1: 9c2c8e744a5864609eb03c68ab1bbf0b3ff3f096 SHA-256: dee21d65b2b6129bc4239be465c0adf54920d76877dc940d2d57d4e23112fb8c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, a technique often used in SEO link farms to manipulate search engine rankings or distribute malicious content. The primary URL suggests a lure for downloading a movie, which is a common social engineering tactic. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/strik?utm_term=shaandaar+full+movie+download+hd+720p+khatrimaza PDF link annotation
    • https://wefopizek.weebly.com/uploads/1/3/4/8/134849363/mapax.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4477629/normal_5ff8a766942f0.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4459057/normal_600b1c4a563ba.pdfIn PDF document text
    • https://kolidazab.weebly.com/uploads/1/3/4/6/134663239/lotixeja.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4401559/normal_5fd7019578615.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4427076/normal_6027758d16f2e.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4443815/normal_5fee0a40dc758.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368976/normal_60615f5a15699.pdfIn PDF document text
    • https://seborokib.weebly.com/uploads/1/3/4/0/134096410/958841ff415.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495975/normal_6060f938b156c.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/5ce40db2-d9ba-4caa-b99e-15f57a0c2d96/rezavawamabumako.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b576e877-b40f-4a2f-90b9-ab810ccb00fc/90336003616.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/edde3aae-b078-4805-af94-e497e5a88f47/meguxajifufiwakotigisus.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/23af89e4-c46c-477a-8035-129084a16813/11_snf_psikoloji_ders_notlar_eitimhane.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6b9fa2a4-f238-471a-9aa5-eb046af95ad8/how_to_set_up_garmin_echomap_73sv.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d09c8e3b-1942-452b-b710-cdd038864451/adobe_premiere_pro_cc_2018_full_version_kuyhaa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/254c7f3c-e9cf-4aec-a9ed-2fe246689d5d/what_makes_a_good_objective.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c00072fc-2b3b-4728-a199-b97d54f79569/t_fal_ultimate_ez_clean_instructions.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f626b128-2bdb-4aee-8db1-5ddf3c2ab7ee/tinexoka.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f8670125-0ad2-4d14-b243-d54f85ce7207/pimp_by_iceberg_slim_movie.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c1a9b902-f76c-4e1e-90b1-f2d9a5b65833/96429580961.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d948.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD948 5824 bytes
SHA-256: 905bed024225b9a3a30e6bb1dd7052f0d2b40162a8fdb85fe1547552b05e0031
font_01_sfnt_off0000ed19.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED19 10416 bytes
SHA-256: 1d71473b6af47408d2cbd8817873bd26da09dd66cd8d55258b827cb8e4d0a114