Malicious PDF — malware analysis report

Static analysis result for SHA-256 e458a2b5d8247810…

MALICIOUS

PDF

86.6 KB Created: 2021-04-01 22:08:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1f73952d765f96cd86d4a275b56dab9a SHA-1: 1ada7f0e06b2e6934f15ec33a937e9369cd8e52d SHA-256: e458a2b5d82478100b407d856a4068c352aae9e80abc4df1602a0d431373370e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains a large number of external links, many of which are obfuscated or lead to PDF files, suggesting a link farm or redirection mechanism. The document body, though heavily corrupted, contains keywords related to search engine optimization, further supporting the lure of external content. The primary IOCs are the numerous URLs pointing to potentially malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9950

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://mezovuduw.ru/wix?keyword=best+home+security+system+2020+uk
    • https://zumusikibalagop.weebly.com/uploads/1/3/4/0/134096359/5be064e4388e002.pdf
    • https://cdn.sqhk.co/kivipemo/gciihgY/luzelak.pdf
    • https://zanelonovubut.weebly.com/uploads/1/3/4/3/134315015/ritasavikaf_tabubufatanufem_vorikido.pdf
    • https://cdn.sqhk.co/pixafosabow/kDn1lii/bluestone_lane_los_altos_reservations.pdf
    • https://rixafewokeget.weebly.com/uploads/1/3/0/7/130739987/652d2f4fb7108.pdf
    • https://cdn.sqhk.co/naxokujim/JGhhcic/eset_parental_control_for_android.pdf
    • https://cdn.sqhk.co/fiwujumejuf/gigdhiW/my_cloud_storage_review.pdf
    • https://zefivevolexu.weebly.com/uploads/1/3/1/6/131637056/1899069.pdf
    • https://kiragidemi.weebly.com/uploads/1/3/0/7/130775435/82fdc54d53961.pdf
    • https://cdn.sqhk.co/fewoxenovof/XWCpjjt/swan_retro_fridge_white.pdf
    • https://niregesop.weebly.com/uploads/1/3/0/7/130776037/jugatek-vosegafalone-tikebakoxelo.pdf
    • http://xikisavi.scienceontheweb.net/saboxixugemobejo.pdf
    • https://bipixexomalexu.weebly.com/uploads/1/3/4/3/134349320/gatakemopararimumov.pdf
    • https://tavefagizukog.weebly.com/uploads/1/3/0/7/130775361/fidagodajuzadetuguj.pdf
    • https://mutomutozuso.weebly.com/uploads/1/3/0/8/130814133/3ca4327.pdf
    • http://vijexibat.mywebcommunity.org/11477880561.pdf
    • https://jaweditulopo.weebly.com/uploads/1/3/4/3/134313576/naxedosenamaraxu.pdf
    • https://cdn.sqhk.co/fuwufupi/oDhihby/51844162856.pdf
    • https://xobisejuzato.weebly.com/uploads/1/3/4/6/134694252/zozaket.pdf
    • https://cdn.sqhk.co/kunimoxifagi/geViege/jifoxiwotinadegarofufigag.pdf
    • https://cdn.sqhk.co/vibisidumes/7Rjh5ic/gelibewefil.pdf
    • https://sajozigita.weebly.com/uploads/1/3/0/8/130814351/dugedeluwopo.pdf
    • https://xosesobo.weebly.com/uploads/1/3/4/6/134697532/8408499.pdf
    • https://jitogomufe.weebly.com/uploads/1/3/4/5/134588764/moxebuzavupup.pdf
    • https://cdn.sqhk.co/zolilobup/HAhcNV0/duo_video_call_app_free_download.pdf
    • http://jezonikiroka.mygamesonline.org/zaton_ka_encyclopedia_urdu_free_download.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://tosurok.myartsonline.com/14045233677.pdf
    • http://kikukuvikato.myartsonline.com/61555228657.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001095a.bin
13bf19050f4b2f59f24a95a7bea00ffcb1a541e57d14c761384d3dfd4de6c2a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1095A 5060 bytes
font_01_sfnt_off00011aa9.bin
24f4cbad05bad0a8e58ac6f8c29f713fe44eb412fa927abc4f576d443440c5b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x11AA9 10488 bytes
font_02_sfnt_off00013e64.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x13E64 4324 bytes