Malicious PDF — malware analysis report

Static analysis result for SHA-256 163e69dc8f77b49c…

MALICIOUS

PDF

65.2 KB Created: 2020-11-25 06:20:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bd10dcb8bed2ea6b18564382f78ab734 SHA-1: eac080c38ec430cec8472c778e10f233154e12ef SHA-256: 163e69dc8f77b49c810fc41dd883dbd2d97d46625d5b4ca4ec72aa50c83017d2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, including a link farm heuristic firing, suggesting a malicious intent to redirect users. The ClamAV detection and ML classifier strongly indicate malicious content, likely a phishing or trojan delivery mechanism. Although no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of techniques used to host malicious content or redirect to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9909

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffi.ru/strik?utm_term=why+we+sing+choir+lyrics
    • https://cdn-cms.f-static.net/uploads/4410695/normal_5fb62881a913d.pdf
    • https://cdn-cms.f-static.net/uploads/4365620/normal_5f87fa1f62ca4.pdf
    • https://cdn-cms.f-static.net/uploads/4402252/normal_5fb69b67d87b1.pdf
    • https://cdn-cms.f-static.net/uploads/4375531/normal_5f89cb086d1ef.pdf
    • https://cdn-cms.f-static.net/uploads/4449187/normal_5fb42f243311e.pdf
    • https://tedovuja.weebly.com/uploads/1/3/4/4/134465286/125921.pdf
    • https://getosadosaponup.weebly.com/uploads/1/3/4/6/134697390/0ffd2.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/vabemavuputenif/xasegawunabo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c5a6.bin
b7b089165bd681e7c4e9cab9d6710dc01dd338dff5d00e092ba6dd0a59e8089e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC5A6 5060 bytes
font_01_sfnt_off0000d701.bin
84f6bd477bca01ad51d6336c5959b7267e3d169daa38e569cdf4bdda98f6f854
pdf-font-stream PDF embedded font (sfnt) at offset 0xD701 9900 bytes