Malicious PDF — malware analysis report

Static analysis result for SHA-256 156bb818043af872…

MALICIOUS

PDF

99.6 KB Created: 2021-06-01 12:56:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 702aed5037fbf572060c70d7660e2865 SHA-1: 2e12827248deeda78cb76682fe16446e4db68787 SHA-256: 156bb818043af872eb81656057fad5207427c84f6f82f4be6b575c8f7a5e666f
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to link farms, which is a common tactic for distributing malicious content or conducting phishing. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware delivery. Although no scripts were explicitly extracted, the PDF structure and numerous external links suggest it's designed to redirect users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9905

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://drafthe.ru/pbw?utm_term=how+to+add+a+pickup+in+noteflight
    • https://kibutabez.weebly.com/uploads/1/3/4/4/134438896/wizajesixuz.pdf
    • https://kogavegi.weebly.com/uploads/1/3/4/8/134873631/adf8cfcea799f.pdf
    • https://pananufizusa.weebly.com/uploads/1/3/4/4/134445813/6943781.pdf
    • https://sijidipej.weebly.com/uploads/1/3/4/4/134483730/robosagefexawa.pdf
    • https://jorikune.weebly.com/uploads/1/3/4/3/134371696/80647206.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://rugewenuzed.pbworks.com/w/file/fetch/144423462/buvirixu.pdf
    • https://uploads.strikinglycdn.com/files/fd2e5ca5-d897-4ad0-a8cc-dea16fdf6973/26793448348.pdf
    • http://fixiguru.pbworks.com/f/pasipomapupuxixamewukibuf.pdf
    • https://uploads.strikinglycdn.com/files/e6ee4cba-d22b-4c8d-a979-938b68e4e58e/99976650536.pdf
    • http://bepisoxu.pbworks.com/f/roburakeg.pdf
    • https://uploads.strikinglycdn.com/files/241dd36b-af29-4753-aacd-8b4c1e71c343/what_does_cirrus_clouds_mean.pdf
    • https://uploads.strikinglycdn.com/files/23295591-805d-41c6-af0b-abf37daf77f3/watch_salems_lot_2004_online_megavideo.pdf
    • https://uploads.strikinglycdn.com/files/26149540-7fd2-465e-8eec-61e6a871c3ef/is_another_twilight_book_coming_out.pdf
    • https://uploads.strikinglycdn.com/files/4fbb41b7-db97-431b-9e00-adacbe148008/pierce_the_veil_chemical_kid_and_mechanical_bride.pdf
    • https://uploads.strikinglycdn.com/files/62aba425-a9ae-4809-80da-c8e377546f39/tokyo_ghoul_anime_finished.pdf
    • https://uploads.strikinglycdn.com/files/6a5c9d79-e36b-49a1-a56f-a9b107de30fe/61665256647.pdf
    • https://uploads.strikinglycdn.com/files/15c22894-4943-4c2c-bafc-de0ee54caf59/wuper.pdf
    • https://uploads.strikinglycdn.com/files/b3653864-b9b5-47ce-bde4-9d007d6bea4d/72467146926.pdf
    • https://uploads.strikinglycdn.com/files/cf64cf3f-bb86-48ea-92e5-8725907cfa93/96049275064.pdf
    • https://uploads.strikinglycdn.com/files/430e7ec0-d99f-4f13-9cf3-b03e5db3ff09/29550806525.pdf
    • http://kokoxudalux.pbworks.com/w/file/fetch/144421200/fichas_para_imprimir_de_las_horas_del_reloj.pdf
    • https://uploads.strikinglycdn.com/files/ff7b34a1-7c23-48f7-afad-32dfb8e331d7/bumuv.pdf
    • https://uploads.strikinglycdn.com/files/9f11d8eb-9108-40f6-b0d9-2e3b404bc004/wodezezepav.pdf
    • https://uploads.strikinglycdn.com/files/89e6dabc-5f4a-4741-b5f6-380bc97e9320/the_watsons_go_to_birmingham_audio_chapter_8.pdf
    • http://fevosezew.pbworks.com/f/how_to_change_infrared_thermometer_from_celsius_to_fahrenheit_model_tg8818n.pdf
    • https://uploads.strikinglycdn.com/files/ba96c89c-b8be-4060-ad81-0ff9620ed1b0/viewsonic_projector_pjd5134_keeps_turning_off.pdf
    • https://uploads.strikinglycdn.com/files/14846fe7-10f7-427a-9c61-a907b46bd981/jawirirasodije.pdf
    • https://uploads.strikinglycdn.com/files/f7bc340b-17a3-493f-816f-3078626cb1f7/35569022102.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000133a3.bin
f058e521d7ec0b7d24b528a7ca148a2ec8dff57823d892ad18b0214e97864b75
pdf-font-stream PDF embedded font (sfnt) at offset 0x133A3 5260 bytes
font_01_sfnt_off0001459c.bin
fc8456b08c09c76468d3facfa42ab6924a461b6d499b26d43611a15f4bf84a7b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1459C 2444 bytes
font_02_sfnt_off00015048.bin
725648f82f3d21f056792b32e3285ffafa381917afb0057ab75ea149b5b54211
pdf-font-stream PDF embedded font (sfnt) at offset 0x15048 11408 bytes
font_03_sfnt_off00017708.bin
74be5bc4d46f64e5c506ae1006f7022dc98ebf960e37c7bf417c2027ca73106d
pdf-font-stream PDF embedded font (sfnt) at offset 0x17708 1736 bytes