Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea955ff471fcdf90…

MALICIOUS

PDF

93.4 KB Created: 2021-03-25 14:47:58 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6f8eabf90b83d03c1c29e3d749bb6f81 SHA-1: 73d4b410ee2a5dabd793d90af154cc5ab16f9c21 SHA-256: ea955ff471fcdf90ae8f536a9231f151e6ce79bd7e07c40746b7fe3b13915388
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with one heuristic specifically identifying a "PDF link farm". The primary suspicious URL, https://leonvi.ru/wix?keyword=bamboo+fly+rod+identification+guide, is likely used for SEO manipulation or to redirect users to malicious content. ClamAV detection and ML classification strongly indicate malicious intent, classifying it as Pdf.Phishing.Trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=bamboo+fly+rod+identification+guide
    • https://bebiluredop.weebly.com/uploads/1/3/3/9/133987060/3471463.pdf
    • https://libizegenumejav.weebly.com/uploads/1/3/0/7/130775388/6547352.pdf
    • https://nelejejo.weebly.com/uploads/1/3/4/8/134883178/7c31e1a75.pdf
    • https://sokirokesavosa.weebly.com/uploads/1/3/4/9/134901907/penedidig-xapoweve.pdf
    • https://mufiguxibetifo.weebly.com/uploads/1/3/1/6/131607440/770b5bbe1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://62bfe9e3-d01a-456c-9d14-3ac71290fd99.filesusr.com/ugd/cfe640_8d7b454d98a04772862b77a0d3900f77.pdf?index=true
    • https://e590c0d9-b694-44fb-9862-47327b30d8b0.filesusr.com/ugd/89363e_82907e6ecfc548eead53371dafb1e188.pdf?index=true
    • https://ec451167-49e0-489e-a150-d7dc0ecf9264.filesusr.com/ugd/fe0276_a793888ab753487bbb0bb11ba753e8eb.pdf?index=true
    • https://s3.amazonaws.com/zonebon/paraphrasing_exercises_with_answers.pdf
    • https://s3.amazonaws.com/ditiruz/15411826021.pdf
    • https://9df6e0af-a028-4e88-91ba-61a1b37318d5.filesusr.com/ugd/7c1f05_587e2fd8377c460194f4e47020c03b24.pdf?index=true
    • https://3f9320ff-391d-49df-b192-c557e211a93c.filesusr.com/ugd/469aea_d3e3848d58724f4d8c44c1fe1111bde6.pdf?index=true
    • https://s3.amazonaws.com/xidazeze/sutisopove.pdf
    • https://07d68bf2-0661-47e2-9ffe-eae068a071af.filesusr.com/ugd/fef806_4809c3481c194d5f8dd293eead35f784.pdf?index=true
    • https://s3.amazonaws.com/folexapurilowe/amman_songs_tamilwire.pdf
    • https://s3.amazonaws.com/zagapaxa/pewenedawubutago.pdf
    • https://810dce77-56ab-4324-823a-3549757f4eab.filesusr.com/ugd/1fad07_1cacdd0cebfe45c588f0dcdc8893a0e6.pdf?index=true
    • https://2d2b1dae-c014-4902-97e6-c3f1d56915cd.filesusr.com/ugd/70e5f7_b9d73a5753d54dd5941a76820a4c68e3.pdf?index=true
    • https://s3.amazonaws.com/nigimul/dovutet.pdf
    • https://93dbb2ad-f1e8-4c6c-adfd-2ef134399473.filesusr.com/ugd/df4650_68bbf8991efc43efb1aafbd5a01c4286.pdf?index=true
    • https://s3.amazonaws.com/donarepemi/los_mejores_cursos_de_ingles_cdmx.pdf
    • https://ff5ab256-a407-4697-91b9-141751226614.filesusr.com/ugd/4205e4_48f924a686bb40febbd5390b9914a45a.pdf?index=true
    • https://181f3bdf-810f-4c34-abb3-9f3362228cd6.filesusr.com/ugd/30415f_375e6cb237de4b07a7abb0fc1a904a56.pdf?index=true
    • https://08b4a39d-fa16-4eaa-91be-ae90003cacb9.filesusr.com/ugd/237bf7_c254e2d11d5e43edb47d9e9955f19c84.pdf?index=true
    • https://s3.amazonaws.com/zesotat/frame_size_guide_glasses.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012180.bin
ca2f746bde12420042a0cab6159b1f1a6092891b45f55f90974b9d66769ba3de
pdf-font-stream PDF embedded font (sfnt) at offset 0x12180 5336 bytes
font_01_sfnt_off00013395.bin
36f7c9ecf1b782b12f96eb7a5156c48dd03355ab528e2d2953e61a2c07b4e0eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x13395 11344 bytes
font_02_sfnt_off00015a13.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x15A13 4324 bytes