Malicious PDF — malware analysis report

Static analysis result for SHA-256 077af3c3b97fc935…

MALICIOUS

PDF

64.6 KB Created: 2020-12-18 01:41:29 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1a4fd65c8653e98a46c69e0723bece57 SHA-1: 791ae569ed60ff907173fe0c964b15b88eac9756 SHA-256: 077af3c3b97fc935f34e40a28c1f6dd08ae1b9b21f20977846cf5ecc8f338b57
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which appear to be SEO-optimized book download lures. The heuristic PDF_SEO_LINK_FARM indicates a deliberate attempt to create a link farm, likely for malicious purposes such as phishing or distributing further malware. The ML classifier and ClamAV detection strongly support the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafficel.ru/123?utm_term=grow+the+f+up+book+pdf+free
    • https://nuwuzeparagagux.weebly.com/uploads/1/3/4/8/134883197/beluwinamu.pdf
    • https://nibawomufexax.weebly.com/uploads/1/3/4/3/134371272/5fdc18bcb.pdf
    • https://cdn-cms.f-static.net/uploads/4418746/normal_5fa2087778332.pdf
    • https://static.s123-cdn-static.com/uploads/4471945/normal_5fc42ac578197.pdf
    • https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/punaju.pdf
    • https://cdn-cms.f-static.net/uploads/4494668/normal_5fd6489b806e7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/f1c1a147-3022-4a93-a7e4-72020da7f94b/earl_sweatshirt_some_rap_songs_downl.pdf
    • https://uploads.strikinglycdn.com/files/92bb69b2-3c0d-4e69-ac3c-5d053d38bb1b/lutikusamako.pdf
    • https://s3.amazonaws.com/sigobija/zaguwe.pdf
    • https://uploads.strikinglycdn.com/files/0e452c74-3073-4d24-bab8-72ed2d72a795/hp_color_laserjet_cp4525_manual.pdf
    • https://uploads.strikinglycdn.com/files/934ae742-6292-4ad0-8f1c-22d2625aa051/29817154309.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c0d1.bin
e84dbc9386d2fc739b3827042b7cfe7a017028ff1b9e784809eaf9d8a31a188f
pdf-font-stream PDF embedded font (sfnt) at offset 0xC0D1 5036 bytes
font_01_sfnt_off0000d1fc.bin
6765e57e25d47ce59fcf23fc802653388cee54f65d493829d2a5b13d902ddce0
pdf-font-stream PDF embedded font (sfnt) at offset 0xD1FC 10500 bytes