Malicious PDF — malware analysis report

Static analysis result for SHA-256 139bbf735ed6ce85…

MALICIOUS

PDF

73.4 KB Created: 2021-05-23 05:57:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-23
MD5: 19d1072a781a555a4ce6fa14ca794fc5 SHA-1: 2e17f7090130e032ca3dc10efdf9bcc9a18b964e SHA-256: 139bbf735ed6ce855e73718edfeac05df1a277752f749b833fc4cc825a71d0bc
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to Weebly and s123-cdn-static.com domains, suggesting a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://baarspo.ru/strik?utm_term=el+kybalion+pdf+espa%25C3%25B1ol+completo PDF link annotation
    • https://tedogiji.weebly.com/uploads/1/3/0/7/130775371/1395405.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4482636/normal_6063f152382c7.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4402289/normal_5fdf35a81f3cc.pdfIn PDF document text
    • https://wolofineso.weebly.com/uploads/1/3/4/5/134598063/9491620b.pdfIn PDF document text
    • https://rifejosowutero.weebly.com/uploads/1/3/4/6/134691359/8e129.pdfIn PDF document text
    • https://luragelekow.weebly.com/uploads/1/3/4/3/134377287/nazuf.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4391621/normal_60151bd8de1f8.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4418192/normal_5feba40faf0cf.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4476590/normal_60063c890b09c.pdfIn PDF document text
    • https://naxujurimarawe.weebly.com/uploads/1/3/4/6/134640244/a2fe843673e7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4386829/normal_6066ecb2b219e.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/mibiwivanetuj/8896157590.pdfIn PDF document text
    • https://s3.amazonaws.com/faluzotixupi/the_son_of_neptune_series_in_order.pdfIn PDF document text
    • https://s3.amazonaws.com/sojebelevenex/easy_savory_vegan_breakfast_recipes.pdfIn PDF document text
    • https://s3.amazonaws.com/fewunadupop/free_weekly_hourly_schedule_template.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/81205a59-0072-437c-9b5f-5eec66b95551/analyzing_baseball_data_with_r_second_edition.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/2e85a941-6016-4dc4-8981-c6b585f65152/sample_memo_to_employees_regarding_safety.pdfIn PDF document text
    • https://s3.amazonaws.com/dumupa/sukugajebafaxoki.pdfIn PDF document text
    • https://s3.amazonaws.com/kujapomib/18_korean_drama_series.pdfIn PDF document text
    • https://s3.amazonaws.com/farefasejikap/sertifikat_akreditasi_program_studi_ban_pt.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cf48.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCF48 5680 bytes
SHA-256: b2f34f830eff8577894ade5d55bda0981a401823f1b68968b17410823e69844e
font_01_sfnt_off0000e24e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE24E 1864 bytes
SHA-256: 614ed29908490b2cf6eaaca9d0091e1e84029f876ebc83a1b5e4ffadee7cd41d
font_02_sfnt_off0000eb5c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEB5C 13336 bytes
SHA-256: 35331e5086e5ee6c37fff02c02ae140d6672af8bc9e0a729665f343e44555d70