Malicious PDF — malware analysis report

Static analysis result for SHA-256 eddb6e0bfe10a735…

MALICIOUS

PDF

77.3 KB Created: 2021-05-23 10:10:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-21
MD5: 9c322fea0d585ee487422a3c6be73feb SHA-1: d376a9f8bb2e263b8bad145201d7db91105de69b SHA-256: eddb6e0bfe10a735c41f936342c5a78b773275335b8cb2393cf2136ad5cf9ba6
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a heuristic firing for PDF_SEO_LINK_FARM, indicating a large number of external links, with one pointing to a suspicious domain. ClamAV also detected it as Pdf.Phishing.Trojan. The presence of embedded URLs and the overall structure suggest an attempt to redirect the user to a malicious site, likely for phishing or to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://midufefew.ru/strik?utm_term=free+california+standard+rental+agreement PDF link annotation
    • https://suzoniku.weebly.com/uploads/1/3/4/4/134456843/8929556.pdfIn PDF document text
    • https://lexawuvake.weebly.com/uploads/1/3/4/6/134610488/jemokevusedozu.pdfIn PDF document text
    • https://kexinebig.weebly.com/uploads/1/3/4/3/134338338/rulovigij.pdfIn PDF document text
    • https://fomodefoz.weebly.com/uploads/1/3/5/9/135958111/vaxokal.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/dca004b6-3677-4ee1-a860-4d847ebe2463/first_alert_smoke_alarm_model_no._7010b.pdfIn PDF document text
    • https://s3.amazonaws.com/tomamujuf/74428798887.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ea66f940-5e07-408f-b421-ef8fd9cf00c2/47446299686.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1cfd89d4-ac94-4dad-8253-a994509a32f6/64118072404.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e193eacb-f99e-4af4-961c-9840fda3b6eb/tasutibokipanunawutagepek.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e979d84d-52b7-4bb2-8ef9-58cfb7e873c1/warcraft_3_reign_of_chaos_patch_download.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/03118bbc-6331-4901-b2e9-f0e8aed5752b/graco_duoglider_rascal_target.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4da78fdd-51dc-45e8-8bc5-a817bd94234a/wiroxanabojeran.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ebbbf1fd-7049-45d2-a6f4-cf92ad844b72/omron_hem-7120_automatic_blood_pressure_monitor_manual.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bf5bf9b1-88ac-445a-8ca8-e54a5f25489d/67822049081.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7e449c8b-2282-43a0-ba00-d19d6af08c38/19189090515.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/52b9a2fb-d20b-4293-bab8-1210678ba14c/93766296801.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/434c9033-9a76-49a7-a2b4-ddbe906cdd28/32618336022.pdfIn PDF document text
    • https://s3.amazonaws.com/vososasoxumete/gikuwegopubalan.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dfa0b573-7e8d-42bf-b484-0323bb66fed6/lolalenubegovijefu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/17562099-2433-4c58-affd-d7f6e81c141b/built_to_sell_audible.pdfIn PDF document text
    • https://s3.amazonaws.com/najipavez/rizapefoze.pdfIn PDF document text
    • https://s3.amazonaws.com/towutoginadivu/brother_hl_2040_printer_driver_download_windows_7.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/60d9899c-2304-43dc-ad34-3b3ec811210f/37119104964.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9fb69c15-89c9-4fa7-9114-40f1e74a3d9f/70582635961.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ef76.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEF76 5296 bytes
SHA-256: 620e0fc90aa8227e02bffd654bf69610474b5f5b8d6f5567147bc807d9b1ea6b
font_01_sfnt_off0001016a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1016A 11152 bytes
SHA-256: b595fc4c1a292b020222476b1a4b5d2be3bd9b59ea7aa1d1b27697b23ab2a1fc