Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2255246d4fbeadf…

MALICIOUS

PDF

76.4 KB Created: 2021-03-09 19:20:26 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 77830a662486ff79aee68a197e81af71 SHA-1: d53ccabb12094c0c2a113b4ee06e8c5048334d5b SHA-256: f2255246d4fbeadf33a396a38fb122ad51f0570b3bfb94372304212748015772
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF containing a link farm and an embedded URL pointing to a suspicious domain, identified as malicious by ClamAV and ML classifiers. The PDF's content, though heavily obfuscated, suggests a lure related to 'autonomous vehicles research'. The presence of external links and the overall detection profile strongly indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://xezojetit.ru/award?keyword=autonomous+vehicles+research+pdf
    • http://pakirekugep.scienceontheweb.net/41384206265.pdf
    • http://getsalon.xyz/baroness_vitamin_c_mask_sheet_reviewhcrt9.pdf
    • http://xefawojuj.mygamesonline.org/juxilalesusemesudo.pdf
    • http://hermidkovo.info/zibibe3pn76.pdf
    • http://xawamiwupajev.mygamesonline.org/16268832766.pdf
    • http://kobazugipodiv.medianewsonline.com/how_to_defeat_a_1-3-1_zone_defense.pdf
    • http://dashcamtopbest.com/kawazbkhxd.pdf
    • http://konsalting.info/suvus0yypu.pdf
    • http://usejus.club/car_battery_tender_charger_reviews50uz1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/28c4c041-96c1-442f-9462-2f55312a5fd6/koxilafapuzisuleluso.pdf
    • https://15319a82-8c66-4906-b3c2-464277991f2b.filesusr.com/ugd/070acf_31fab4b5209c4a0d8fde091d998510c5.pdf?index=true
    • https://s3.amazonaws.com/bomupi/81501896172.pdf
    • http://vekejuf.atwebpages.com/what_is_considered_middle_class_in_alabama.pdf
    • https://uploads.strikinglycdn.com/files/40c2d4c9-9775-4cf0-ad0d-6e2b62f3655a/the_alienist_book_review_new_york_times.pdf
    • https://s3.amazonaws.com/nabifovu/ganpati_dj_song_full_bass.pdf
    • https://s3.amazonaws.com/legipalofi/dashboard_in_excel_templates.pdf
    • https://s3.amazonaws.com/moduluzuxikari/business_vocabulary_in_use_advanced_cambridge.pdf
    • https://s3.amazonaws.com/wunojipu/university_english_vocabulary_list.pdf
    • https://uploads.strikinglycdn.com/files/b470ae8e-310d-423d-bc74-7ccb20cf381b/on_writing_well_summary.pdf
    • https://s3.amazonaws.com/xedewofuretujo/girujizuza.pdf
    • https://s3.amazonaws.com/nitizobuv/13758633180.pdf
    • https://153f2bed-3501-4ec5-9468-ed1987511f6d.filesusr.com/ugd/f67134_e04e22330a624d648de66b7443ea4fdd.pdf?index=true
    • https://s3.amazonaws.com/fovezewi/kixijemob.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ed8b.bin
b7abbb1ba1acb136e7dc1a20dbd671ec86697a93fb062fea890e32ad9a65aa33
pdf-font-stream PDF embedded font (sfnt) at offset 0xED8B 5444 bytes
font_01_sfnt_off0000ffed.bin
856c8a3b4ad553a350ea6110ca6fe886271170b98d5c38166b704f8284c8712c
pdf-font-stream PDF embedded font (sfnt) at offset 0xFFED 10680 bytes