Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb2de721991963b9…

MALICIOUS

PDF

87.9 KB Created: 2021-03-15 22:37:34 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5657611fc23e8c5afab5dafeab432d24 SHA-1: bfa4b56ce00f4bc89826a7977a678e0c8713628c SHA-256: eb2de721991963b9dce107a811fa25c5d1dfb21da83e7de307a1a39c4ef1aebe
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of external links, many of which are dynamically generated, suggesting a link farm or SEO spam operation. The document body, though heavily obfuscated, appears to be a lure related to a common household problem, designed to encourage clicks on the embedded malicious URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=what+to+do+if+washing+machine+door+won%2527t+open
    • https://cdn.sqhk.co/jigugabopu/wieghL7/basuvukitudaruxufupige.pdf
    • https://cdn.sqhk.co/jimumakevaji/d8hdHji/39431993664.pdf
    • https://gobadinemi.weebly.com/uploads/1/3/5/2/135299992/jewus.pdf
    • https://zatiwakap.weebly.com/uploads/1/3/1/8/131871625/mumavobijifapaw-rifujonewalera-nifafuwojajo.pdf
    • https://cdn.sqhk.co/feneradebeza/hcPPmzT/what_does_contemplate_mean_in_literature.pdf
    • https://nifirasevaxo.weebly.com/uploads/1/3/4/7/134756957/8824852.pdf
    • https://dowamodugepaxa.weebly.com/uploads/1/3/0/7/130739159/2215323.pdf
    • https://zulunapakaf.weebly.com/uploads/1/3/1/0/131070820/jagedugaladi.pdf
    • https://cdn.sqhk.co/jotapepikota/RxseijU/96243599175.pdf
    • http://balonedud.iblogger.org/sitodu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://0fc0baf9-b884-4fcd-968e-f93c0f938930.filesusr.com/ugd/68ec51_cccbc7ae56f54446998c0219e467014a.pdf?index=true
    • https://4cd5a77a-be8d-44ba-8952-4177873115c4.filesusr.com/ugd/930050_e62635a46fc64e3d91e67eb86aeea2d5.pdf?index=true
    • http://peburameg.epizy.com/free_indesign_architecture_portfolio_layout_templates.pdf
    • https://64b67c6e-fbbd-4787-add8-9ed3e274c95c.filesusr.com/ugd/eb6612_2d0bc3172ab84f3bb9d654cb4ac66492.pdf?index=true
    • https://45f61934-b4a1-4335-a9e3-e142d9465b5b.filesusr.com/ugd/0dd040_c664791cc997472ab97169464ce02115.pdf?index=true
    • http://naxelekifomo.rf.gd/fazavanawex.pdf
    • https://80172413-d145-4b71-b7cf-4a007d76ad29.filesusr.com/ugd/cacfd7_241a3d2a75a24f46a25d40d139fef89b.pdf?index=true
    • https://8fc1c2d6-49ba-4d63-8b95-0327ef2b1627.filesusr.com/ugd/1849a1_5c20557401564b1cb6ddd74ffe9c6079.pdf?index=true
    • https://ff87c8b5-ca28-4ac0-94ba-218234037d87.filesusr.com/ugd/1d4e4f_bb7f46e674c84f37a03eaaf1ac0d5548.pdf?index=true
    • http://zosatomoviwom.rf.gd/asus_p8z77-v_le_plus_cpu_support.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001046d.bin
9909bd8786e9dc73a991eb63eed9e8ae1b9cfec0a96fa1711a3f5ff8e53aa7f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1046D 5676 bytes
font_01_sfnt_off000117bb.bin
cc48f6f64ddb55a077e403e128bc378c10c031eb7c4d5aa9cd394dcaf93ed88d
pdf-font-stream PDF embedded font (sfnt) at offset 0x117BB 10768 bytes
font_02_sfnt_off00013c7d.bin
64f21e55c2f29c6f605e8f9fd96e7f7b34f9b4a26fdc717ddead948457370e3b
pdf-font-stream PDF embedded font (sfnt) at offset 0x13C7D 16148 bytes