Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea2c092a1145d094…

MALICIOUS

PDF

85.6 KB Created: 2021-03-28 22:18:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 72e91fe89c8340fd21016ebcce41acb4 SHA-1: 01861a3946b6c8f482a3b9737388120ae5da58b9 SHA-256: ea2c092a1145d094550b989c5347ab43d1bd7aa1644389d885e80ac42f67c590
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a mass external link farm, with many URLs pointing to other PDF files, indicating a phishing or spamming operation. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of a phishing lure designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xajibur.ru/123?utm_term=news+opening+after+effects+template+free
    • http://organize.shop/kannada_challenging_star_darshan_photos89hr9.pdf
    • http://kiwirixup.22web.org/dclaration_du_chiffre_d_affaires_auto_entrepreneur_maroc.pdf
    • https://newakikijako.weebly.com/uploads/1/3/4/3/134351088/0841eb8.pdf
    • https://tonefomemozev.weebly.com/uploads/1/3/4/4/134458928/3022007.pdf
    • http://paypallsecurity.com/36431386204oep9y.pdf
    • http://venira.su/teeth_occlusal_caries_tonsils_gums_report17789.pdf
    • https://dapijapivabug.weebly.com/uploads/1/3/4/3/134338952/wakerupugujigulive.pdf
    • http://dream-stat.ru/pumimevigo78e8c.pdf
    • https://doxizuzipoleri.weebly.com/uploads/1/3/5/3/135323895/xamifala.pdf
    • https://febasenijig.weebly.com/uploads/1/3/1/3/131379808/zawor_lusedufigebid_kexuki_nanoposif.pdf
    • https://balimalovi.weebly.com/uploads/1/3/2/7/132710770/pakovawositi.pdf
    • https://sobomimaseneke.weebly.com/uploads/1/3/1/3/131379860/b3b78d23be2d8.pdf
    • https://lowujowe.weebly.com/uploads/1/3/5/3/135320741/f3037164bd68.pdf
    • https://pupiwukonavi.weebly.com/uploads/1/3/2/6/132682553/6254132.pdf
    • https://dixozetazexode.weebly.com/uploads/1/3/4/4/134472526/c0fa6690c.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://xegiseko.epizy.com/kobeleda.pdf
    • https://4b67404f-136a-46a0-9cf3-151f2d38faab.filesusr.com/ugd/241fd5_0bc59df73559440c8ec2253c2b7e2197.pdf?index=true
    • https://5663e088-3595-439c-971a-5873693bee35.filesusr.com/ugd/e98895_e64a97c084ed41c1a9fa3fc8cd154ea7.pdf?index=true
    • https://a2c67b61-a01d-4053-b7ad-f1487bca8054.filesusr.com/ugd/24853a_c41384472e25420eaf167a0bf83aefc4.pdf?index=true
    • https://6f2fb29c-15f2-4b08-b525-3eb91a7f0a41.filesusr.com/ugd/c3548c_b78e5884466a44658dcb02a46b7438c9.pdf?index=true
    • https://8f1ef4f7-3f23-41ef-a3d6-4e5873a175a2.filesusr.com/ugd/d318ce_8f9a9bb82bb3475281865a255bcd592d.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010f40.bin
3b07646ecb7f527675ae445ed2a22eacec9bc06abce3ef1ce5117014612568cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F40 5396 bytes
font_01_sfnt_off000121a7.bin
7c0d9f52ed48221c3ff245559850319fc0a77ff5c4ca79bd424ee8aedb219f79
pdf-font-stream PDF embedded font (sfnt) at offset 0x121A7 11088 bytes