Malicious PDF — malware analysis report

Static analysis result for SHA-256 027ed7adbb356f30…

MALICIOUS

PDF

76.3 KB Created: 2021-03-28 10:36:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6da0d686b37c884b89544091514d30ad SHA-1: a58a39d1ca84b2be1576fd33e30b0c1ebf0dfd73 SHA-256: 027ed7adbb356f3063851ceac374362b9c663c8e610ddab118bdadfe2b2fa286
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic identifying a link farm designed to host malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The presence of embedded URLs suggests an attempt to redirect users to potentially harmful sites for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9832

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://dafemum.ru/award?keyword=panasonic+aw+ue150+pdf
    • https://vefoxetewezelir.weebly.com/uploads/1/3/1/4/131483279/8291649.pdf
    • http://sevoxotedeki.medianewsonline.com/i_am_from_poem_examples_for_high_school.pdf
    • http://timinome.getenjoyment.net/agregador_de.pdf
    • https://kisotupojez.weebly.com/uploads/1/3/4/4/134493444/2357114.pdf
    • https://gumewixolasadaz.weebly.com/uploads/1/3/4/6/134659592/4ce62406.pdf
    • http://barajofa.mywebcommunity.org/pawizotuxelupipevamasisu.pdf
    • http://golixudib.mypressonline.com/antibiotics_during_pregnancy.pdf
    • http://mimivamefigupe.sportsontheweb.net/vovonosesu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://borepojoga.epizy.com/69857871363.pdf
    • https://s3.amazonaws.com/fifuto/bartender_ultralite_version_10._0.pdf
    • https://s3.amazonaws.com/nutanigonu/cisco_lab_guide.pdf
    • https://s3.amazonaws.com/taturi/kerala_railway_station_code.pdf
    • https://s3.amazonaws.com/pibajuwi/tajobipademew.pdf
    • https://s3.amazonaws.com/xesigeze/kemiven.pdf
    • https://s3.amazonaws.com/bokexizometun/windows_10_update_stopped_ing.pdf
    • https://s3.amazonaws.com/setikizo/phases_of_the_moon_lesson_plan_1st_grade.pdf
    • http://sajurewe.rf.gd/mental_health_counselor_job_description.pdf
    • http://bexalaxawuwe.rf.gd/24027391133.pdf
    • https://s3.amazonaws.com/jifesu/waxesituwezojivanemu.pdf
    • http://rurebafib.onlinewebshop.net/benefejusifa.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eb3e.bin
a28fcc4ba65d8171a55e8b87d646ac5d1dd213f66ab2b0026fd39e5ca5d32d1a
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB3E 2900 bytes
font_01_sfnt_off0000f580.bin
eb575f2a20941defd0932b48b539f5470d342c77bb6751757a93d3b4998a5243
pdf-font-stream PDF embedded font (sfnt) at offset 0xF580 5432 bytes
font_02_sfnt_off00010831.bin
6e408479cd7426f4e305063ef652a1abfb35089862c9f0ad77e3795c301a1504
pdf-font-stream PDF embedded font (sfnt) at offset 0x10831 11644 bytes