Malicious PDF — malware analysis report

Static analysis result for SHA-256 f76c3e61052c99de…

MALICIOUS

PDF

123.9 KB Created: 2021-05-26 23:46:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f8e562a308e2f4222d2b6b6f7af0753e SHA-1: d2e331410502333cf5792edd40721bea1ab0546c SHA-256: f76c3e61052c99dee7ec0824f0092ae16fd2d69644d86f0dea5047b451b9af38
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The presence of a PDF link farm heuristic and numerous embedded URLs, including one pointing to 'botokaw.ru', suggests a phishing or SEO manipulation attack. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of techniques used to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=homicide+squad+new+york+cases+cheats
    • https://lemuvizavo.weebly.com/uploads/1/3/2/6/132682731/3332506.pdf
    • https://wajufavex.weebly.com/uploads/1/3/4/5/134587400/rivebitek_dibotusuferapun.pdf
    • https://votumojelobi.weebly.com/uploads/1/3/4/8/134848055/verevaki.pdf
    • https://mesobesin.weebly.com/uploads/1/3/4/5/134590010/9067243.pdf
    • https://garevanixuxud.weebly.com/uploads/1/3/4/3/134371644/b0b9eded16f0fc.pdf
    • https://sobaxijuxoje.weebly.com/uploads/1/3/4/2/134235367/dakibojolaxifem.pdf
    • https://xipunozelizu.weebly.com/uploads/1/3/1/3/131382486/gejamuvetuxurokenur.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ac95572a-90a8-449e-a8b2-dc5842784f10/international_business_universities_in_texas.pdf
    • https://uploads.strikinglycdn.com/files/9635c66a-771b-43f6-97e1-7d7609bff204/what_is_the_dead_sea_scrolls_doomsday_prophecy.pdf
    • https://uploads.strikinglycdn.com/files/11138275-7d39-4959-9155-8024dfe4d737/moto_g_power_user_guide.pdf
    • https://uploads.strikinglycdn.com/files/edec0ddf-31f5-46a7-881e-8d78af940da0/what_is_the_warranty_on_schlage_locks.pdf
    • https://uploads.strikinglycdn.com/files/b4f8dfed-3ff4-4c8c-8a00-cabf62605015/metal_gear_solid_3_pc_release.pdf
    • https://uploads.strikinglycdn.com/files/9552a756-d7a6-430f-90be-a217f92eae1d/a_practical_handbook_for_the_actor.pdf
    • https://uploads.strikinglycdn.com/files/d16685cc-408d-43a9-a114-a04d41c6ba52/xivosedurusofaxepiboner.pdf
    • https://uploads.strikinglycdn.com/files/b0c3089a-6aa4-47cf-a3a9-320fc31b0014/netgear_prosafe_switch_default_password.pdf
    • https://uploads.strikinglycdn.com/files/f4cf433c-0f9b-463c-8ffa-2024c91694fa/9959273768.pdf
    • https://uploads.strikinglycdn.com/files/4a65f544-4c94-43c1-b02d-191a4a16895f/how_to_say_quran_in_english.pdf
    • https://uploads.strikinglycdn.com/files/4f3fd21e-710d-45c3-b9f5-f9a2429dde15/veworinodibisaxabunugazu.pdf
    • https://uploads.strikinglycdn.com/files/ee983665-7325-4483-8b7e-4647b4d5ed45/wii_rvl_001_replacement_laser.pdf
    • https://uploads.strikinglycdn.com/files/7f8a39ab-8634-4652-a56a-c0bf8564ef9d/zutidoxawoni.pdf
    • https://uploads.strikinglycdn.com/files/af8f2157-bd73-4deb-8572-4405fd2c8425/68788603261.pdf
    • https://uploads.strikinglycdn.com/files/e245d71b-7d0a-4f12-9b07-22d07ed3b5ed/14085506978.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001130c.bin
ccaf06b8a8ec54704278f99c093499bd497ceb0f4f2c971ab13556bff6673f52
pdf-font-stream PDF embedded font (sfnt) at offset 0x1130C 5492 bytes
font_01_sfnt_off00012597.bin
e59cd9a128750d3ba5996bccc272881c186461f916121f3dd37e05fa92c25bd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x12597 41384 bytes
font_02_sfnt_off000198d2.bin
16f13d466b34b1a51b340107362f5520198b1e7b3d0b64bb0ad571ce1b48fab8
pdf-font-stream PDF embedded font (sfnt) at offset 0x198D2 11592 bytes
font_03_sfnt_off0001bfd3.bin
7c3dd4ad5913c8dbbbddac6a0b8679fe5bff8cb5c80e9d9f1b75c365870cf239
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BFD3 20052 bytes