Malicious PDF — malware analysis report

Static analysis result for SHA-256 e41e28ebdc200ae7…

MALICIOUS

PDF

76.6 KB Created: 2021-03-07 11:52:00 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e98e71e41b2c4d9550abab9178377ab2 SHA-1: f06e10765c4a71b64430f9aba6bc03901c72c69a SHA-256: e41e28ebdc200ae7b5be7701a2694c044334d07dc51c3c3f1299a84578a702d8
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, indicating malicious content. It contains a large number of external links, many of which are SEO-related, and one prominent URL that mimics a search result. While no scripts were explicitly extracted, the PDF structure and the presence of numerous external links suggest an attempt to redirect users to potentially malicious sites, possibly for SEO spam or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/wix?keyword=ventajas+y+desventajas+de+facebook+lite
    • http://terakusinuw.mypressonline.com/edu_science_telescope_50-360_manual.pdf
    • https://nebofubegifeso.weebly.com/uploads/1/3/1/4/131437549/8989438.pdf
    • http://movawizaxaxato.mywebcommunity.org/sunbeam_heated_blanket_directions.pdf
    • https://xitirume.weebly.com/uploads/1/3/4/3/134392652/nenulavareziwubulimo.pdf
    • https://nedilobimizedov.weebly.com/uploads/1/3/5/3/135346130/lafusutinim-zimodobufaxaj-wetitopit-sifigovo.pdf
    • https://litukepulaj.weebly.com/uploads/1/3/4/8/134863372/vofupugemurep_maferuvakuxe_zezebaba_dakodesip.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/dewazewokib/quiz_logo_game_level_20_answers.pdf
    • https://s3.amazonaws.com/nufidibodudulad/bikroy_app_for_android.pdf
    • https://s3.amazonaws.com/turip/45515024404.pdf
    • https://uploads.strikinglycdn.com/files/0a6bc332-20a0-4a4d-b5b6-b8718ce45f02/is_wendys_spicy_chicken_salad_healthy.pdf
    • https://s3.amazonaws.com/loxopudizus/walamojuw.pdf
    • https://s3.amazonaws.com/lixisariwulo/89350040159.pdf
    • http://pevipitoz.atwebpages.com/vorojavozusilerozoxenegiz.pdf
    • https://uploads.strikinglycdn.com/files/480385a1-9625-4f54-88dd-663803b132c9/grunch_of_giants_espaol.pdf
    • https://uploads.strikinglycdn.com/files/cb85b15d-6960-4334-9045-968b7ec20eab/business_mathematics_course_outline.pdf
    • https://uploads.strikinglycdn.com/files/9efa1b94-8a9b-41c3-b9cc-4cc952e6fa96/tasco_trail_camera_reviews.pdf
    • http://zokemunerepefu.rf.gd/bhojpuri_video_dj_m4.pdf
    • https://s3.amazonaws.com/goviwigax/departmental_exam_dec_2018_answer_key.pdf
    • http://xazisiloxumu.rf.gd/rufosiwoxakoguxuxofuke.pdf
    • https://s3.amazonaws.com/golepe/68801197856.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ead6.bin
3e6aacb3737682d680bd6a435273c007e5c223cffd0f80c41674d7917d3040ec
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAD6 5324 bytes
font_01_sfnt_off0000fd21.bin
d0a5e2165d8ef0d5a0a0ce5231e78333d7097e80ebf16b431f49c46e80cd6cca
pdf-font-stream PDF embedded font (sfnt) at offset 0xFD21 11748 bytes