Malicious PDF — malware analysis report

Static analysis result for SHA-256 098dd62fda378a74…

MALICIOUS

PDF

80.6 KB Created: 2021-04-02 06:05:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2c06f5eb976b99620167ba2e9dfa9cae SHA-1: 93bceeaaa76ae46819a02a9809f3859988874b0a SHA-256: 098dd62fda378a749650e576e580eb6c2c432cabf37c31b025e0bba454e6f4e7
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are SEO-optimized, suggesting a link farm or phishing attempt to drive traffic to potentially malicious sites. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution disguised as a software download. No scripts were extracted, but the PDF structure and external links point towards a lure for potentially unwanted or malicious software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://golowaki.ru/award?keyword=adobe+pdf+reader+free+download+windows+8+64+bit
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://3176e400-c268-4dc0-8d69-08eae86937f8.filesusr.com/ugd/ea2f88_63bf6c4a261f4eecb77aa13d26652e94.pdf?index=true
    • https://uploads.strikinglycdn.com/files/87fa87f0-d075-4232-b152-b6fef15b4f10/gas_dynamics_john_and_keith_3rd_edition.pdf
    • https://uploads.strikinglycdn.com/files/42df701b-0b35-4ec2-a497-3649ed56f3da/soundcraft_ui12_price.pdf
    • https://s3.amazonaws.com/zonebon/types_of_ownership_structure.pdf
    • https://s3.amazonaws.com/nelizenejakarug/ebay_kleinanzeigen_app_alte_version_android.pdf
    • https://a95edb9d-21e5-46e4-bb1b-b1fdf66a5dae.filesusr.com/ugd/09e34a_7203240ef8fb4623a68f5859296b0872.pdf?index=true
    • https://cf336f9a-6a79-4542-9269-5b62d6eb69dd.filesusr.com/ugd/1daf83_09cb6d860c53407d91431e069c4109ce.pdf?index=true
    • http://judenagu.epizy.com/90897470897.pdf
    • https://1ac5d900-0c69-4f12-8b1d-4e209472b8d2.filesusr.com/ugd/828753_9c7f96e6c36c436cbb58d766bd1dda6c.pdf?index=true
    • https://s3.amazonaws.com/fizufapu/janatha_garage_video_songs_mp4_telugu.pdf
    • https://s3.amazonaws.com/xidazeze/web_designer_resume_template_free.pdf
    • https://s3.amazonaws.com/rabewiruzitewa/angels_and_demons_book_setting.pdf
    • https://uploads.strikinglycdn.com/files/6eee951b-c4f2-4ef5-a66c-7fc9b65fa10c/22396622884.pdf
    • http://xifupojodu.epizy.com/xbox_360_controller_wireless_to_wired_convert.pdf
    • https://s3.amazonaws.com/xedewofuretujo/xazibotejup.pdf
    • https://1639490a-f715-481e-9fb1-af38d332269b.filesusr.com/ugd/a59130_7db8d75ce86c463880c5f37ef9080e75.pdf?index=true
    • https://e7c02ae7-ba66-49ef-8fe7-d4c265c54a1b.filesusr.com/ugd/bc5701_93a9b7eb05244514b09da5d75b667330.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f169.bin
3ae64ce97c15bbe56ee997392b345cac125d83fe868418ff2d1294bfb0830d72
pdf-font-stream PDF embedded font (sfnt) at offset 0xF169 5480 bytes
font_01_sfnt_off00010420.bin
d916d6efe74977cf96c9b7c98f859f7e79426ca350f28b978eb49290e1e42a1c
pdf-font-stream PDF embedded font (sfnt) at offset 0x10420 10204 bytes
font_02_sfnt_off0001270e.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x1270E 4324 bytes