Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3b96f5baeb3b68c…

MALICIOUS

PDF

109.9 KB Created: 2021-04-08 06:58:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 50a1edb33944aa257b9bc28abf58f801 SHA-1: e5e2428265d81b4934d7172ccce1310624a92e2d SHA-256: e3b96f5baeb3b68cc44e16ae901ed1a6eae9982e76420b95001738605e7ee9fd
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file exhibits characteristics of a phishing lure, directing users to external URLs under the guise of 'Ftse 100 companies reporting today'. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting an attempt to generate traffic or distribute further malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/123?utm_term=ftse+100+companies+reporting+today
    • https://cdn.sqhk.co/sijiposago/jiSUYY2/dunkin_donuts_sandwich_menu_calories.pdf
    • https://cdn.sqhk.co/fefowofuk/aL26yge/microban_24_hour_spray_reviews.pdf
    • https://cdn.sqhk.co/guwaloxipete/Sgehjih/steampunk_syndicate_mod_apk.pdf
    • https://cdn.sqhk.co/tojebaru/0U374n1/63709019973.pdf
    • https://cdn.sqhk.co/mumesimasozo/BUjjfwH/2021_starcraft_311bh.pdf
    • http://larekew.mywebcommunity.org/collins_scrabble_dictionary_free.pdf
    • http://sosogemizibu.mypressonline.com/93707179715.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://9eb5ee95-128e-4115-bcd6-d8db8525ce49.filesusr.com/ugd/9904c2_5cd19080af024d40b7e9404a8e2dee80.pdf?index=true
    • https://562c2315-396f-49d1-9e45-1236e049cb13.filesusr.com/ugd/ec0012_c91653006e434327b6f9b9049952034d.pdf?index=true
    • https://s3.amazonaws.com/fivebo/pokemon_usum_battle_tree_guide.pdf
    • https://329f26c8-0235-4118-8622-173d264d9cf1.filesusr.com/ugd/221f3a_ff32017b86014732a21423da52994b6d.pdf?index=true
    • https://5b5cf7c4-d983-4e27-bd54-44d52fc9074e.filesusr.com/ugd/2f9450_f4ad4516190a4c14a6af9257bcc6f80a.pdf?index=true
    • https://fb075467-9d00-46c6-93ac-2b777f5e584b.filesusr.com/ugd/8bcd66_2be32c0e68f645fb8c59d5f7d70831de.pdf?index=true
    • https://c3f0ce02-b953-40d9-b94a-e38a054f9a35.filesusr.com/ugd/7afb62_4b60e442b0444cc7b568b556a9d57ca7.pdf?index=true
    • http://kubomefewofumim.atwebpages.com/gokugadosibanuxug.pdf
    • https://c039f79f-855f-4b64-8838-30138aeea086.filesusr.com/ugd/6b78cb_dbfc89cec49f4ed8bf7b8e2c5dc7024b.pdf?index=true
    • https://4a7d9d2b-1d67-446c-8d6d-bdd3043d1f60.filesusr.com/ugd/c3d078_8c6db83d184c4435a0f30daa7cef7e31.pdf?index=true
    • http://folapopapewoxa.rf.gd/50729122979.pdf
    • https://d62ff7d9-aefc-4ab8-8cdf-af38868aea16.filesusr.com/ugd/54b9a1_d5af103aa28e4302a8cd8fdf37b531fc.pdf?index=true
    • http://nepogewapiw.epizy.com/12305415424.pdf
    • https://s3.amazonaws.com/zakunafu/selenium_webdriver_tutorial_java_eclipse_with_examples.pdf
    • http://zukomakiduw.myartsonline.com/setaxuxanunawanu.pdf
    • https://s3.amazonaws.com/kewakuko/customize_extent_report_in_selenium_c.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00016bb1.bin
b84bf7fb3b2e96c9d2c3a971cd8a3bca158107cf044ffe2d0fac9a2fdb3c48bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x16BB1 5612 bytes
font_01_sfnt_off00017ebc.bin
535464715caf0abd7acbdc08c6a6b4331eaf9be1103b13b6f0d9ef1b8cd5c9e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x17EBC 12720 bytes