Malicious PDF — malware analysis report

Static analysis result for SHA-256 0a4991a72f420bab…

MALICIOUS

PDF

65.3 KB Created: 2020-11-27 10:07:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b7ac67d6c98eca1a9c919d733b524b33 SHA-1: 19c22bf75ac65767a11e8fb71285ae91f135504c SHA-256: 0a4991a72f420baba8a1950e046e44bfa9a35dd8eeb3b8cdebe19dcaafc75648
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to Weebly-hosted PDFs, indicating a link farm designed to distribute malicious content. The ClamAV detection and ML classifier strongly suggest malicious intent, likely related to phishing or malware delivery. Although no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/aws?utm_term=template+arlina+design+terbaru
    • https://mebudowafiwene.weebly.com/uploads/1/3/4/6/134629245/fotizevogeb-sozunuxujigup-bitowugovuzi.pdf
    • https://kexawugidatenak.weebly.com/uploads/1/3/4/3/134338825/d2a53ad8dcdd82.pdf
    • https://cdn-cms.f-static.net/uploads/4426543/normal_5faf33c84db09.pdf
    • https://bigonokefexix.weebly.com/uploads/1/3/4/5/134518339/funalagerefimim.pdf
    • https://sasakafu.weebly.com/uploads/1/3/4/3/134371045/fcdb3872547ed4f.pdf
    • https://sizonijuza.weebly.com/uploads/1/3/4/5/134594560/remibivemufiluwi.pdf
    • https://cdn-cms.f-static.net/uploads/4365552/normal_5faa0fe92b899.pdf
    • https://komavumi.weebly.com/uploads/1/3/0/7/130738531/rabibom_lixopukakiwa_liraja.pdf
    • https://bilewazivabo.weebly.com/uploads/1/3/2/8/132816117/bilozox.pdf
    • https://cdn-cms.f-static.net/uploads/4366408/normal_5f873ed4bc9d3.pdf
    • https://cdn-cms.f-static.net/uploads/4365600/normal_5f8a69068874e.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/0aae7662-db85-4dd6-9fe2-6bb8abd44ce3/rokilovefozumomeme.pdf
    • https://s3.amazonaws.com/xedewofuretujo/coc_hack_2020.pdf
    • https://uploads.strikinglycdn.com/files/8b96f39f-f46d-4da6-891e-0fd44ad6491f/tuzikizanebokelo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c3cb.bin
7b867fc7078ef97e1a40c5409acb808968fb1c286bf69d10691c83c39863c4c1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3CB 5368 bytes
font_01_sfnt_off0000d5e8.bin
483a2db9bb7277be8f9acb4727165eaec0751d7046896883daf0bdb67796a762
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5E8 10144 bytes