Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e1fa44a7a3780cf…

MALICIOUS

PDF

87.6 KB Created: 2021-03-16 23:57:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c492caacd959f4eef069a21618ae793d SHA-1: b26e61c4db8ed84a2741694eccc1708ad048ff28 SHA-256: 2e1fa44a7a3780cfeb45e1a0099a7df3fe9e42dc91e11203de4128d2c18d519a
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, with one identified as a malicious URL hosted on 'ponafet.ru'. This suggests the document is designed to redirect users to potentially harmful content, likely for phishing or malware distribution. The ClamAV detection and ML classifier further support its malicious nature. No scripts were extracted, but the presence of numerous external links indicates a primary function of directing users to external resources.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/strik?utm_term=thay+%25C4%2591%25E1%25BB%2595i+t%25C3%25AAn+c%25C3%25B4ng+ty+tr%25C3%25AAn+h%25C3%25B3a+%25C4%2591%25C6%25A1n+%25C4%2591i%25E1%25BB%2587n+t%25E1%25BB%25AD
    • https://gumomerad.weebly.com/uploads/1/3/1/8/131856086/8493723.pdf
    • https://betetudiju.weebly.com/uploads/1/3/5/3/135348010/lufigegowasumanuxaw.pdf
    • https://losebevaxefot.weebly.com/uploads/1/3/5/3/135347065/ropepe.pdf
    • https://labegemi.weebly.com/uploads/1/3/4/7/134709462/pukekenomevefu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/suxugipipolazog/august_2019_sat_reddit.pdf
    • https://uploads.strikinglycdn.com/files/441088fa-a626-4025-a7d6-9e547db05bbb/kigoperilojofarokavi.pdf
    • https://s3.amazonaws.com/muvarelo/how_to_become_a_soccer_referee_in_southern_california.pdf
    • https://s3.amazonaws.com/vikukinumet/wedding_invite_text_template.pdf
    • https://76df98a8-3e94-4eee-a6f5-23e1de06049b.filesusr.com/ugd/54c74c_9a463f670584496396b09a718778c80e.pdf?index=true
    • https://uploads.strikinglycdn.com/files/b622539f-d126-47d7-9463-35ba6360c724/50013644997.pdf
    • https://933527c5-e005-4225-a3aa-05fee46c7696.filesusr.com/ugd/b51dd5_fbab254940cb4b4d986b66216d89b5a3.pdf?index=true
    • https://uploads.strikinglycdn.com/files/20e541d8-345c-4221-af6f-b6b05d9a0ae9/difference_between_viral_and_bacterial_infection_in_cbc.pdf
    • https://uploads.strikinglycdn.com/files/75b7e565-5db3-4a1d-a540-af2a9724f15e/cheap_hp_5520_printer_cartridges.pdf
    • https://s3.amazonaws.com/jadudusujuje/92676543847.pdf
    • https://571cbd0a-ba82-408d-be6d-2df53a8fcfe5.filesusr.com/ugd/02af14_eb598910d755496a9547743b0bd840da.pdf?index=true
    • https://d4bcd744-2348-4fe3-9006-05b2fcbd3cbd.filesusr.com/ugd/704566_1ec09301f81444539c997359a6ab21e5.pdf?index=true
    • https://uploads.strikinglycdn.com/files/5caefc19-5cc0-40c8-b75d-e9812cf47cd5/wewotebubilupaminupana.pdf
    • https://c02a3fa2-970f-4384-b4fa-7a60184a1b73.filesusr.com/ugd/1da3fe_74d3c33b53334335a2a2244bfbbf49b3.pdf?index=true
    • https://33edd578-4186-4695-89f3-f56a5a23fc53.filesusr.com/ugd/f17c08_28f26077f408421d951bd29b62535873.pdf?index=true
    • https://s3.amazonaws.com/jotizifime/android_keyboard_aosp_4._2._2.pdf
    • https://2c8134a4-d865-4da1-8961-c755d7242105.filesusr.com/ugd/6dcf04_c223260f3fd64beebdca36ec3c9f45b6.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000eaf3.bin
ffeb89eaad713c9717385028f79c9757067aafb2c2382ea8cbab0e6efe35a425
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAF3 6744 bytes
font_01_sfnt_off0000fbdb.bin
33e557e9a3b4e20aa8a6f0e2268380be7be10d8b4b161ba4f3f44b405937a003
pdf-font-stream PDF embedded font (sfnt) at offset 0xFBDB 5744 bytes
font_02_sfnt_off00010e4c.bin
f63d79aa7524f6ca3d1f668facf7116160157b77b94c44000c19d24be7b64d42
pdf-font-stream PDF embedded font (sfnt) at offset 0x10E4C 22212 bytes
font_03_sfnt_off00013ff8.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FF8 4324 bytes