Malicious PDF — malware analysis report

Static analysis result for SHA-256 02a115c6c569f23a…

MALICIOUS

PDF

73.8 KB Created: 2021-06-09 16:19:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5e8d3e361d25df529f5b821b40bd457a SHA-1: b4fd108777af5781285d2fc7b8ef575cec10bcf2 SHA-256: 02a115c6c569f23ae8e77d21cb39efea112e41b7ba5991e5a936c5cb70b284bd
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to PDF files hosted on file-sharing services, indicating a link farm designed to distribute malicious content. The ClamAV detection and ML classifier strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and extensive external linking are indicative of a phishing or malware distribution campaign, likely initiated via spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://smidgel.ru/pbw?utm_term=fazbear+frights+book+3+pdf
    • https://zetokefukakebep.weebly.com/uploads/1/3/1/4/131438441/8245713.pdf
    • https://namosozevo.weebly.com/uploads/1/3/0/9/130969937/a652cb9805e1.pdf
    • https://cdn-cms.f-static.net/uploads/4366647/normal_5fe6fb7dba5f7.pdf
    • https://paduxadoduxim.weebly.com/uploads/1/3/0/7/130775016/733676.pdf
    • https://zojobowexiwe.weebly.com/uploads/1/3/1/3/131380894/725653.pdf
    • https://karuxuli.weebly.com/uploads/1/3/4/3/134377251/1289384.pdf
    • https://cdn-cms.f-static.net/uploads/4385228/normal_606035d5e8bb6.pdf
    • https://cdn-cms.f-static.net/uploads/4368266/normal_6015b88e756ab.pdf
    • https://static.s123-cdn-static.com/uploads/4502248/normal_60091ddb7d185.pdf
    • https://cdn-cms.f-static.net/uploads/4421335/normal_6039143cbaadd.pdf
    • https://wekexodaxax.weebly.com/uploads/1/3/4/7/134713384/tujamerunopodod.pdf
    • https://cdn-cms.f-static.net/uploads/4383446/normal_5fd68b3c1f137.pdf
    • https://cdn-cms.f-static.net/uploads/4382189/normal_603f0116ec5d6.pdf
    • https://sasinulipig.weebly.com/uploads/1/3/7/5/137512958/lefegamivakun-jalilufag-seledezijukefel.pdf
    • https://dojibosuxuzepi.weebly.com/uploads/1/3/1/3/131378780/2628298.pdf
    • https://cdn-cms.f-static.net/uploads/4465277/normal_60292180c0608.pdf
    • https://rixukofet.weebly.com/uploads/1/3/4/1/134108779/4777860.pdf
    • https://sinegozedajosor.weebly.com/uploads/1/3/1/8/131871849/zuxoganepunevusefux.pdf
    • https://cdn-cms.f-static.net/uploads/4380674/normal_60241fb313cd3.pdf
    • https://vadidavulegisiw.weebly.com/uploads/1/3/4/7/134760242/gitonasukoge.pdf
    • https://cdn-cms.f-static.net/uploads/4485689/normal_602988bb145be.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e104.bin
ed08b7dc9c77c5abf4121600d28cd2720495e229d807ac069c33dabc9c9f40b6
pdf-font-stream PDF embedded font (sfnt) at offset 0xE104 5644 bytes
font_01_sfnt_off0000f438.bin
9997ba2af91d3ca68961879b22a783c9194492a9d60f3087707a2d1d7cc129c8
pdf-font-stream PDF embedded font (sfnt) at offset 0xF438 11156 bytes