Malicious PDF — malware analysis report

Static analysis result for SHA-256 132a4acb929e1263…

MALICIOUS

PDF

81.9 KB Created: 2021-03-28 15:04:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bf27ec66dce8fe803bd72912edc84a16 SHA-1: 2fe34f8adaea7455967c1f0a1bd9a2ba79fd9730 SHA-256: 132a4acb929e1263cc72757e92c1e31952ac800d58dd363903d26033b3a1d887
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged by multiple heuristics as malicious, including ClamAV detection and an ML classifier. It contains a large number of external links, many pointing to PDF files hosted on file-sharing services, suggesting a link farm or phishing campaign. The document body is heavily obfuscated and appears to be generated content, further supporting the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jacksth.ru/wix?keyword=chicken+nesting+box+plans+pdf
    • https://wuzovogupo.weebly.com/uploads/1/3/4/7/134720757/e5524cc9c.pdf
    • https://gaxirakim.weebly.com/uploads/1/3/4/6/134605205/51dcb365abfd.pdf
    • http://lassituda.online/wutozezipoviboluvarolosifet8i.pdf
    • https://lolisusije.weebly.com/uploads/1/3/4/6/134627287/5045533.pdf
    • http://sitizinudex.getenjoyment.net/psalm_23_verse_6_afrikaans.pdf
    • https://vazigawexike.weebly.com/uploads/1/3/1/6/131606690/zuralanolewejo-gavife.pdf
    • http://opensalle.xyz/what_are_the_key_things_in_a_healthy_relationship9j7tc.pdf
    • http://creditscoretracking.info/diccionario_de_metodologia_dela_investigacion_cientifica_ortiz_uribeembzm.pdf
    • http://kasewokagirit.iblogger.org/19775872720.pdf
    • https://ritefebeg.weebly.com/uploads/1/3/5/3/135316582/xabezene-togijujoxumer.pdf
    • http://nemagufi.mywebcommunity.org/simple_english_grammar_free_download.pdf
    • http://smilex.club/unicorn_gundam_02_banshee_norn_instructionswut7h.pdf
    • http://sdfsdfsdf.shaketorch.com/android_file_transfer_mac_not_working_2019.pdf
    • http://tomogorman.com/13301770618fvsib.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://desujiruvomeb.myartsonline.com/tulavat.pdf
    • https://e06e8306-d71e-4c92-aa1b-e8c52eeb44cb.filesusr.com/ugd/bc4951_661496394c774af79bc42dd87bc2215b.pdf?index=true
    • https://d03ec42c-8b93-48d3-a61e-9aee396c0db4.filesusr.com/ugd/1e557c_73628e237b324d80aaad9720ade66a7b.pdf?index=true
    • https://56db2a4d-09ce-4ff6-a558-abb1d6727cd4.filesusr.com/ugd/003b86_30983defcafd4842b8751a8f3a8d0f03.pdf?index=true
    • https://fa886832-b9e3-4ce5-a98c-97da2614721f.filesusr.com/ugd/9f8050_e627ac7179fb41b7a7c9a528aecbdb72.pdf?index=true
    • http://wuxosalilujaza.atwebpages.com/61307070466.pdf
    • http://sebukojuteropib.rf.gd/recommendation_letter_for_teacher.pdf
    • https://72dfff08-f6cb-4f5d-aaac-ebe71175d6a6.filesusr.com/ugd/c268f7_e4eec758a5b548a5966177c5a3e0b2c4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f264.bin
ce58f1ec27ef739c7eea95df9c99e261dc67540f16b848f403001419750f1836
pdf-font-stream PDF embedded font (sfnt) at offset 0xF264 5404 bytes
font_01_sfnt_off000104b5.bin
96a379ad1215620fb385764f15481ea558cff69b412b55efa4eddc895f150db8
pdf-font-stream PDF embedded font (sfnt) at offset 0x104B5 10960 bytes
font_02_sfnt_off00012a14.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x12A14 4324 bytes