Malicious PDF — malware analysis report

Static analysis result for SHA-256 1b30cf7fd8961cb3…

MALICIOUS

PDF

103.0 KB Created: 2021-03-23 06:42:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 9b475ed94174562c2cf55f299835bbfc SHA-1: 12cba470bdaa3229fb71445dbb2cf0c9898c8d03 SHA-256: 1b30cf7fd8961cb384f073522db2a0e651e221f6e95130605aed91d48f18c7fa
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a link farm, with the primary URL pointing to a suspicious domain. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9978

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/123?utm_term=akun+vsco+fullpack+gratis+2019+android PDF link annotation
    • https://tapogizixe.weebly.com/uploads/1/3/4/8/134897788/2ea4d908.pdfIn PDF document text
    • https://cdn.sqhk.co/wefegiwezon/8jdjjsE/small_gym_business_plan.pdfIn PDF document text
    • https://leniwexobopusez.weebly.com/uploads/1/3/4/7/134713406/4180598.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4379221/normal_5fe7e97d6cccd.pdfIn PDF document text
    • https://firupafawaxif.weebly.com/uploads/1/3/4/1/134109114/7885488.pdfIn PDF document text
    • https://nifatukipukixe.weebly.com/uploads/1/3/1/3/131398430/7139966.pdfIn PDF document text
    • https://cdn.sqhk.co/sawapevodef/ggHQxhi/monkey_preschool_lunchbox_apk_free.pdfIn PDF document text
    • https://zopixidasopotid.weebly.com/uploads/1/3/1/3/131397955/ruzafuxeralu.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4416798/normal_601ad31d3b7f3.pdfIn PDF document text
    • https://cdn.sqhk.co/gitovera/gd5gijf/pro_smash_players_allegations.pdfIn PDF document text
    • https://cdn.sqhk.co/xolofiwano/ihjijNx/42492633929.pdfIn PDF document text
    • https://jevamupoledi.weebly.com/uploads/1/3/4/7/134712268/9775709.pdfIn PDF document text
    • https://rovagurepuj.weebly.com/uploads/1/3/1/8/131856033/zofinavodowil.pdfIn PDF document text
    • https://funogumoduwe.weebly.com/uploads/1/3/4/3/134309977/fegugiwivadapa.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/miledu/online_marksheet_verification_cbse_board.pdfIn PDF document text
    • https://s3.amazonaws.com/negonanopix/how_to_install_waterboss_900.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba83fa5d-9877-41af-82fd-248dd12bea39/85899246258.pdfIn PDF document text
    • https://s3.amazonaws.com/megujobemegor/mefituzerifedozipajawewu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d3383d67-cbd1-4099-9825-00717442d74c/41576381329.pdfIn PDF document text
    • https://s3.amazonaws.com/vifusupegiza/goonersguide_betting_tips.pdfIn PDF document text
    • https://s3.amazonaws.com/kasuwevovog/79670957596.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/9eac1be2-37af-4059-90c7-d866abbac6df/jasoviloni.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010539.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10539 6588 bytes
SHA-256: fa72874b8c381873b432d3b5cea9ecddba20f04e8e1c9face7d560df1136061a
font_01_sfnt_off00011582.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11582 2988 bytes
SHA-256: 991aedf0fd0dd49657b0b1af788d5902e0ca9741571727e475d0942e72673e1e
font_02_sfnt_off00012032.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12032 5916 bytes
SHA-256: bac6f50db6df449e644c79ea1f88544a980e36b58497ca5895a563286b70007c
font_03_sfnt_off00013471.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13471 7416 bytes
SHA-256: 5ef793091bf95a0313b8636ab9d46e0228e6db06725da9c8e4c38c04a201deca
font_04_sfnt_off00014d78.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14D78 11604 bytes
SHA-256: 36e06569d631b6c1a230be27daa6d332625e549214d16083ba69c309ae439ef2
font_05_sfnt_off00017577.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17577 16280 bytes
SHA-256: 27e1239a99f6b792b8335504a4900658c9e56d4f27c91f47d55e2b57094015e9