Malicious PDF — malware analysis report

Static analysis result for SHA-256 0478a49a8c0227af…

MALICIOUS

PDF

77.9 KB Created: 2021-03-17 18:47:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c744af3d90c9484271482cd58c4f7578 SHA-1: 907efe252ac7972e29554a8d9d8a68f92e1a8199 SHA-256: 0478a49a8c0227afb2094c6d67335c6c4c794b7abccedb68fbfc05625c6fb21a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document, identified as malicious by ClamAV and an ML classifier, contains a large number of external links, many of which are hosted on benign-looking domains but point to other PDFs. The primary malicious URL is golowaki.ru, which is likely used for phishing or to host further malicious content. The document's content is obfuscated, but the presence of numerous links suggests an attempt to direct users to potentially harmful external resources, possibly as part of a link farm or phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/123?utm_term=pc+build+guide+philippines
    • https://wimiwimevodozaz.weebly.com/uploads/1/3/0/8/130874111/592818.pdf
    • https://renupipa.weebly.com/uploads/1/3/4/3/134383378/8b7460.pdf
    • https://cdn.sqhk.co/xezufulozuwo/bD0gigj/out_there_edition_download.pdf
    • https://cdn.sqhk.co/xokekekav/jggdZjh/57824711892.pdf
    • http://myirn.icu/what_is_extracorporeal_membrane_oxygenationdssey.pdf
    • https://cdn.sqhk.co/moxelutedoje/jkGs2jh/monument_valley_utah.pdf
    • http://upsbox.ru/33135511150cqm9r.pdf
    • https://sefokuto.weebly.com/uploads/1/3/0/7/130738721/3529633.pdf
    • https://cdn.sqhk.co/leluforeref/hhrigYU/90758037012.pdf
    • http://zeropium.com/stanley_wet_dry_vac_bags_8_gallonf3o1u.pdf
    • http://fastpysystem.online/jump_attack_tim_grover_review7ew78.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/5f87d6d0-7338-4b82-b850-4a7f8468ebb0/65048400300.pdf
    • https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_2825799ad525442bbe35de5b4325614e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/9d00299a-ced4-4d5f-8846-bf23ad136044/72998310573.pdf
    • https://e8dc5420-792a-4861-90db-09cfc8d8a7d1.filesusr.com/ugd/1378f5_ef37776c616441568e0d7dce7f85cf59.pdf?index=true
    • https://uploads.strikinglycdn.com/files/863f95e2-54e4-467f-9694-ed237acd4544/black_and_decker_toaster_oven_manual_to3260xsbd.pdf
    • https://a2fe464c-28d1-4db8-bb2d-552ad9bc2f4d.filesusr.com/ugd/941bb1_bda4d04efc864be7b98ec24fc1e3b854.pdf?index=true
    • https://uploads.strikinglycdn.com/files/ad82eb0f-c835-4d36-9111-45557c1720f2/74808446645.pdf
    • https://ef4b221f-cfb4-47e8-bf1d-3b5092770df7.filesusr.com/ugd/4948da_c08b3ea11ea74ac884d639cf3af1812a.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f4c3.bin
f77cee7bbe9535b27d10c7413daed22a42fda47be01f5244e79270eade8d5a06
pdf-font-stream PDF embedded font (sfnt) at offset 0xF4C3 5172 bytes
font_01_sfnt_off00010652.bin
e48b79bf76efaf15e71abf011edef59ba7eb512cae944db5de59205f0ebbdb24
pdf-font-stream PDF embedded font (sfnt) at offset 0x10652 10580 bytes