Malicious PDF — malware analysis report

Static analysis result for SHA-256 e80de2c143220fa5…

MALICIOUS

PDF

78.0 KB Created: 2021-02-21 18:44:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: ceae97ebf4d48084ce3a90757373a6d9 SHA-1: eadbe65409a8ec48f2c8ea221c3ab7bb65f8f3f3 SHA-256: e80de2c143220fa5988603454685c2af52c0cf92feaaeec073cf0c1c9f8bc530
196 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a link farm, suggesting an attempt to direct users to malicious websites. The presence of a password-protected archive lure indicates a common tactic to bypass security scanning. ClamAV detection and ML classification further support its malicious nature, likely as a phishing or malware distribution vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 6

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/123?utm_term=best+fighting+anime+2020 PDF link annotation
    • https://cdn.sqhk.co/somepizeko/6iggiWk/mazorigag.pdfIn PDF document text
    • https://xorizelipuv.weebly.com/uploads/1/3/1/6/131637744/5fb28e.pdfIn PDF document text
    • https://vuzeruferule.weebly.com/uploads/1/3/4/5/134591890/bitozazipikuzoxukit.pdfIn PDF document text
    • https://cdn.sqhk.co/norifasil/jbhbdqd/movesus.pdfIn PDF document text
    • https://cdn.sqhk.co/bebuvasipen/TpEYZhg/how_to_draw_easy_cartoon_dog.pdfIn PDF document text
    • https://fizupubiwox.weebly.com/uploads/1/3/0/7/130775838/noxovovixun.pdfIn PDF document text
    • https://cdn.sqhk.co/vafodagusun/iihihj8/30157686751.pdfIn PDF document text
    • https://cdn.sqhk.co/dowotovewi/hdKhgtb/billie_eilish_songs_listen_online.pdfIn PDF document text
    • https://wudusalulolatus.weebly.com/uploads/1/3/1/6/131606476/d08e06b5b9fe9b5.pdfIn PDF document text
    • https://cdn.sqhk.co/viwiratoposu/aM6oVhg/rizeja.pdfIn PDF document text
    • https://cdn.sqhk.co/gekobegij/Y1jhcUU/guxutixiganebatosab.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fazujo/chrome_store_adblock_android.pdfIn PDF document text
    • https://s3.amazonaws.com/bupaxomu/goodwill_donation_value_spreadsheet.pdfIn PDF document text
    • https://s3.amazonaws.com/lomogas/guided_access_iphone_lost_passcode.pdfIn PDF document text
    • https://s3.amazonaws.com/suxuzubojut/how_to_apply_for_marriage_contract.pdfIn PDF document text
    • https://s3.amazonaws.com/fefurorobumi/bahamut_esper_ffbe_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/pibabopuduj/sprawlopolis_rules.pdfIn PDF document text
    • https://s3.amazonaws.com/zepifudoxapo/alkaline_songs_list.pdfIn PDF document text
    • https://s3.amazonaws.com/rovikibixu/85002895184.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f10b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF10B 5376 bytes
SHA-256: 348cbead58e0261a812946324b0e99db08be00aee00f938191de0a03d8e56fb9
font_01_sfnt_off0001033c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1033C 11828 bytes
SHA-256: cd488fc5076124430bf29888d90556479bdcd83646a521052c52d23840859403