Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1ae16d073c3a1b7…

MALICIOUS

PDF

76.0 KB Created: 2021-03-27 17:02:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9861f73b1301b7a8d99eba1acedc6c11 SHA-1: 6e725ce28faf7891f1a71e57307a4254b3daf92d SHA-256: e1ae16d073c3a1b7e7215e1271db01e9fece11988b08914418845fda00ea759f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, indicating a link farm or phishing attempt. The document body, though heavily obfuscated, suggests a lure related to "Appareil respiratoire anatomie pdf" to drive traffic to these external URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/award?keyword=appareil+respiratoire+anatomie+pdf
    • https://cdn.sqhk.co/nisikevepoxi/b5jfijU/get_likes_views_for_instagram_hashtags.pdf
    • http://2gusevshop.space/8691299675kjxtg.pdf
    • https://cdn.sqhk.co/vedanoderifu/Yij94gj/14030714369.pdf
    • http://wildboost.club/asla_pes_etme_1_turkce_dublaj_indir6cd4w.pdf
    • http://grusha.space/rojifibukujolidomosgyvqn.pdf
    • https://cdn.sqhk.co/zatovafer/YhggiC5/20594901932.pdf
    • https://cdn.sqhk.co/dagufiwus/jbdihhb/bluetooth_serial_terminal_commands.pdf
    • https://cdn-cms.f-static.net/uploads/4371244/normal_605548dbb2779.pdf
    • https://cdn.sqhk.co/wodaximewule/Xrqhege/best_ringtones_2020.pdf
    • http://joblanc.xyz/53596923745yvlae.pdf
    • https://cdn.sqhk.co/zolususux/hCDifaJ/vitamin_shoppe_coupon_august_2020.pdf
    • https://cdn-cms.f-static.net/uploads/4485318/normal_601db713dd945.pdf
    • https://static.s123-cdn-static.com/uploads/4371800/normal_5fcb5c61172a7.pdf
    • http://technodom11.com/4095943674101lj.pdf
    • https://cdn-cms.f-static.net/uploads/4467017/normal_5fd7cbd7b600e.pdf
    • https://static.s123-cdn-static.com/uploads/4406216/normal_5fc6b9c9484eb.pdf
    • https://cdn.sqhk.co/kajurineg/QgcpgcB/jubepusubejasotowigurez.pdf
    • http://casbah2point0.com/place_value_through_thousandths_worksheetstw4x0.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://a79fbd7c-12a6-44fe-9d3c-43dc2b0795a8.filesusr.com/ugd/f95141_7ba1264d1886420785f1530bd4c79f36.pdf?index=true
    • https://cb47f074-0476-4434-b381-5672a365cab8.filesusr.com/ugd/c46c8a_c267bfd7966f4a8baa7c0a13f589e902.pdf?index=true
    • https://198d5876-2e36-4a54-a59d-b4c1060b65be.filesusr.com/ugd/4733ca_2ec2f0501ae9408fb96784c744fa4663.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e8df.bin
e2b978ed834273237354d30b1b680d8eaa6eb728ab1a98eaaed1a3b87e7c0d4f
pdf-font-stream PDF embedded font (sfnt) at offset 0xE8DF 5176 bytes
font_01_sfnt_off0000fa63.bin
32fefdba6cca41f71b6e5e483a9927fdd123fa3f0e98e2c9995926a1b3669956
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA63 12656 bytes