Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7b088e42794c8c9…

MALICIOUS

PDF

80.6 KB Created: 2021-05-12 12:31:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: be25d3804b47cf43569b2219783eb778 SHA-1: 75a4c783c99577b213111ebf12f531b5d9e4bbd3 SHA-256: e7b088e42794c8c9b2d8eb6480023fed4f61865e22928d015ae10e735da3bdc1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one heuristic specifically identifying it as a 'PDF_SEO_LINK_FARM'. The primary malicious URL, 'https://botokaw.ru/strik?utm_term=delonghi+pac+an125hpek+specs', suggests a potential phishing or scam lure related to product specifications. ClamAV and ML classifiers also flagged this PDF as malicious, indicating a high likelihood of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=delonghi+pac+an125hpek+specs
    • http://jafoxidulez.mypressonline.com/bacaan_shalat_sesuai_sunnah.pdf
    • http://jaralet.getenjoyment.net/uat_test_plan_template_example.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/4adc4393-1161-418f-a717-bd3162d63f6c/vajodeken.pdf
    • https://72858ab8-d36f-4bc2-b208-e5ec56e76d01.filesusr.com/ugd/3a4e0e_66e4976734324b4dac36e9b4bc5be7c8.pdf?index=true
    • https://uploads.strikinglycdn.com/files/6e7d6d12-b5c4-41ad-88f3-7b658d43e433/after_we_collided_release_date_2020_netflix.pdf
    • https://081e7fb2-604d-424b-9b75-a58d54a71a44.filesusr.com/ugd/abd6ea_f594efa9a9374ff2ab7deb0b0a1a14d6.pdf?index=true
    • https://s3.amazonaws.com/rijaliwiguvex/52564319313.pdf
    • https://c02a3fa2-970f-4384-b4fa-7a60184a1b73.filesusr.com/ugd/1da3fe_ea021a6c25e54c7fb93a57ade4927fe9.pdf?index=true
    • https://uploads.strikinglycdn.com/files/63198373-7e62-415f-9ffb-fcbf9f31f364/41749590932.pdf
    • https://s3.amazonaws.com/remufuzu/93561549.pdf
    • https://7fad2989-91b8-457c-89bc-9a0e7aeef19f.filesusr.com/ugd/b03ff3_1ec4347bdf6a42d98b418d117cdf49b5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/199afca7-1262-442c-9479-03de64054036/18_hands_of_lohan.pdf
    • https://uploads.strikinglycdn.com/files/5325dd26-1acb-45da-b476-62b599779b63/fifty_shades_darker_soundtrack_youtube_playlist.pdf
    • https://uploads.strikinglycdn.com/files/84dac381-2d0c-4b2a-af51-4bac1aedb374/19754408759.pdf
    • http://zujakogi.onlinewebshop.net/ruwekuletozodopuvekoj.pdf
    • https://uploads.strikinglycdn.com/files/1f9c8512-94ca-45b4-9b14-b718dd9cbba3/driver_hp_pavilion_dv6_win_10_64_bit.pdf
    • https://uploads.strikinglycdn.com/files/bde25c3b-b5fc-427d-a68e-3e9b35b889d8/kunijijobanunelezeg.pdf
    • https://30bb9d03-04f1-4043-8ca4-b11f08dd7d37.filesusr.com/ugd/82ab19_2168181b41d34c01a62c5215a958a472.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef08.bin
9805a3b4373b34479bede1177ddaa17dbed7ec8ba434331387bed1211c27d73f
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF08 5180 bytes
font_01_sfnt_off000100a7.bin
3d7b5756940323f27407af058f816d84ca1bc1f83eda5f5fac76af528f68cc84
pdf-font-stream PDF embedded font (sfnt) at offset 0x100A7 11176 bytes
font_02_sfnt_off000126ee.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x126EE 4324 bytes