Malicious PDF — malware analysis report

Static analysis result for SHA-256 18bad14f55d78e31…

MALICIOUS

PDF

118.4 KB Created: 2021-06-01 06:20:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-07-07
MD5: a704959b768db3a2c5e7d26f41b85581 SHA-1: 5d6fcb0fd85f7b64e52c840d45cbc8538e1a788d SHA-256: 18bad14f55d78e318e510241b578cdfd95df561ca752528341fa0ebd6c782c5e
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, flagged as a link farm, with one primary malicious URL identified. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and link farm heuristic suggest it's designed to redirect users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9994

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://chcial.ru/pbw?utm_term=mahaprabhu+sri+chaitanya+colors+bangla+serial+song+download PDF link annotation
    • https://static.s123-cdn-static.com/uploads/4479705/normal_6003391374589.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4469623/normal_5fcc8447b37cc.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4457839/normal_600b3f500e8cb.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4474719/normal_5ff662aa2fb4d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4366331/normal_605f72f7d5d33.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4495973/normal_602b5dd409585.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4387219/normal_60551c70bbf6f.pdfIn PDF document text
    • https://kanemonel.weebly.com/uploads/1/3/5/3/135319287/a13f6bbe.pdfIn PDF document text
    • https://befadileniralan.weebly.com/uploads/1/3/6/0/136082268/3529186.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/fd9453c5-e3c7-4fac-ba9e-f4234d33d7fb/80263863587.pdfIn PDF document text
    • http://wuwazilizos.pbworks.com/f/41261868018.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ab7b6339-abbf-4fa4-9f71-214481669df8/99367701740.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3473b463-7c05-4828-95ba-f15bcb69ba31/sezunalakasimesumapu.pdfIn PDF document text
    • http://bofamawetodo.pbworks.com/f/que_significa_sonhar_com_a_cara_desserto.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/96622f6d-ad9c-46fa-87b4-28b4087841ff/melarisiwuzebotedad.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e67853ba-62ce-4dac-9347-690fc28e92cd/what_are_the_order_of_operations_in_excel.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/09f1921b-f0ac-48c1-a5c9-7836d5f9e90b/how_to_clean_bissell_proheat_2x_after_use.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ec7ee2c3-e039-40c4-9e25-1391374d0ef4/minecraft_bookshelf_layout.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001559d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1559D 5676 bytes
SHA-256: 875ac4a426b136aa0d376f3583b05e9fc4688181da969f1f55972a5672e4f3ae
font_01_sfnt_off00016902.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x16902 6024 bytes
SHA-256: ca603ac12245db54992ea2f6339d234de58b8fa0d01bb4d9358ffeb6dd9bb8e2
font_02_sfnt_off00017c6c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17C6C 1908 bytes
SHA-256: 3f842c02fbac7cdf8e596d5ac77d08a6055a5f1c81ca9c37f406ec9b2a338c3c
font_03_sfnt_off000185be.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x185BE 15180 bytes
SHA-256: 621cdff8a68f922334f25e134d1a1673784c11ce93fb11c9a2bfed2a388b608d
font_04_sfnt_off0001b42b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1B42B 16060 bytes
SHA-256: bb4620ae2308066493f479cb0495314a41e91f5b0bfb2a754d9bad2ef34af03d