Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3d58ac1d909f0e6…

MALICIOUS

PDF

84.6 KB Created: 2021-03-31 04:11:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b4dbd692a42a635d7fe31749b894f330 SHA-1: 2b03ed3e0168a16e69f4f1418ef081d24a9f342a SHA-256: f3d58ac1d909f0e6b2e3cf7db9fc1d25a205c2d7f51c0966070f333beb2f2f1e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one heuristic specifically identifying it as a 'PDF_SEO_LINK_FARM'. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. The embedded URLs suggest a redirection mechanism to potentially malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9992

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/wix?keyword=it+essentials+chapter+5+study+guide
    • https://cdn.sqhk.co/xeloxilava/uhbooGR/pba_tour_bowling_2019_tv_schedule.pdf
    • https://cdn.sqhk.co/redusebi/iimiapd/jufusenowulojaxosanaxeje.pdf
    • https://cdn.sqhk.co/wepurodapike/hbFhiLn/49748271872.pdf
    • https://cdn.sqhk.co/navimoxa/hbJuGBB/kilidezosojasewi.pdf
    • https://cdn.sqhk.co/putomikoluku/h5Sgjhb/satizoxufad.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://fc060a1e-8c1d-4b7d-bafd-75f79d4c6355.filesusr.com/ugd/c0a468_ed13022802c34e99adebb4a0621ac1de.pdf?index=true
    • https://uploads.strikinglycdn.com/files/4e0498b5-3c07-4e60-bcd6-854cc29972ab/girudowat.pdf
    • https://uploads.strikinglycdn.com/files/cbf6b0e9-8ad9-48d4-ab02-f165e3e2b469/62271518163.pdf
    • https://uploads.strikinglycdn.com/files/924be6c4-e779-4c66-87a0-75a29558ee72/94020356762.pdf
    • https://3e021c9a-284a-4c54-9ba1-f6d43d4d2ba5.filesusr.com/ugd/a619af_79ffee9dbb1c4d6ba7562b57bf5e3f77.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d55d58f5-e1e8-4bc6-b4b1-426cc7a2ceb0/are_lg_stylo_5_good_phones.pdf
    • https://s3.amazonaws.com/juvetaso/problem_statement_template_slide.pdf
    • https://uploads.strikinglycdn.com/files/50f029a0-1c12-44d9-8f9a-4b10a49eb5de/mibafaxifatisowaz.pdf
    • https://uploads.strikinglycdn.com/files/da287479-b6e8-4df7-a695-c6391e2b936e/how_to_clean_maytag_bravos_xl_washer.pdf
    • https://d5e9a058-cbdc-4968-ba72-30cdbf1e36a3.filesusr.com/ugd/9cfd0a_4fe2915d7c9242e0b565544d7c1c689e.pdf?index=true
    • https://083189c9-8220-4687-a375-57be19a37228.filesusr.com/ugd/909b15_47ff637ced634a238dcc0eaab00c89e1.pdf?index=true
    • https://uploads.strikinglycdn.com/files/641f66a0-3ff6-40aa-9ea7-02858d4d3b33/fitijesenojarofadozitubix.pdf
    • https://uploads.strikinglycdn.com/files/4acb7e5b-04e0-4da3-9585-0e6a061b5684/what_is_the_order_of_the_amory_wars_books.pdf
    • https://s3.amazonaws.com/kefiperizonofu/guided_journaling_for_depression.pdf
    • https://uploads.strikinglycdn.com/files/d8e7dd02-d86a-4321-a75b-6eb27df7cb43/mini_dv_camcorder_player.pdf
    • https://s3.amazonaws.com/votubukaxogilix/52025912974.pdf
    • https://72cee60b-533f-4fda-9f40-87b1bb6f0553.filesusr.com/ugd/590778_259ba465a0f64807859c718d881bd4ac.pdf?index=true
    • https://s3.amazonaws.com/zuvovoxigumuz/vuzoxa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fe0a.bin
58d26081721f87a3b864061d6a2dada99388d62f440e726cce3c707e4d246ecd
pdf-font-stream PDF embedded font (sfnt) at offset 0xFE0A 5268 bytes
font_01_sfnt_off00010fe5.bin
6fd8ec3fe425d4c251d48826132f2808598b3fae6c923fcd3a8a0c673553009a
pdf-font-stream PDF embedded font (sfnt) at offset 0x10FE5 11584 bytes
font_02_sfnt_off000136a1.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x136A1 4324 bytes