Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f05651646f3e6ae…

MALICIOUS

PDF

86.0 KB Created: 2021-02-28 03:04:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: f3e1a3c8a48b3a7a607edc40bf3194d8 SHA-1: f27d687373130fee57c0f6224e1751ea5851bd0c SHA-256: 2f05651646f3e6ae5a2e756c13a8c42e5f7acf4a92e36010876b43b3a3319f89
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, flagged as a link farm, and the document body, though heavily obfuscated, appears to be a lure related to a popular book. The presence of external URIs and the ML classifier's high confidence score indicate malicious intent, likely to redirect users to phishing or malware sites. While no scripts were explicitly extracted, the PDF structure and heuristic firings suggest it's designed to exploit users through deceptive content and external links.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jumiwimov.ru/123?utm_term=resumen+de+la+obra+el+diario+de+greg+1+un+chico+en+apuros PDF link annotation
    • https://cdn.sqhk.co/tetolonul/vMSJgct/16368918030.pdfIn PDF document text
    • https://cdn.sqhk.co/jezaziritav/jiqicjg/words_in_a_pic_2276.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4485573/normal_6016edb3d3122.pdfIn PDF document text
    • https://cdn.sqhk.co/wuvitatutuv/yhiIBhj/20636222501.pdfIn PDF document text
    • https://cdn.sqhk.co/kanojasav/hDhcLds/ralepagamigibabebetozax.pdfIn PDF document text
    • https://zirotowaze.weebly.com/uploads/1/3/1/0/131070424/530b4354cc.pdfIn PDF document text
    • https://cdn.sqhk.co/mevazasid/hKhbkid/today_s_date_in_spanish_with_the_year.pdfIn PDF document text
    • https://cdn.sqhk.co/zezoxomop/f1ibGjf/how_to_use_winky_lux_eyebrow_pencil.pdfIn PDF document text
    • https://cdn.sqhk.co/nokulebepoba/x9ziamo/6064965862.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4404497/normal_602a3f6eed549.pdfIn PDF document text
    • https://bexoligimes.weebly.com/uploads/1/3/4/3/134314561/bf7bd3e6c2e38.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451544/normal_6022919494e97.pdfIn PDF document text
    • https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/nafuwu_bokivorurazu_vofokis.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://s3.amazonaws.com/wifukedot/42008879002.pdfIn PDF document text
    • https://s3.amazonaws.com/jubiferekaka/80307330641.pdfIn PDF document text
    • https://s3.amazonaws.com/lakadutof/19884637160.pdfIn PDF document text
    • https://s3.amazonaws.com/fusopoxipo/zibufotigenedoxukemetegan.pdfIn PDF document text
    • https://s3.amazonaws.com/jenisozazewubo/riworijigazugavuwig.pdfIn PDF document text
    • https://s3.amazonaws.com/latufenaw/behind_enemy_lines_2_android_game_download.pdfIn PDF document text
    • https://s3.amazonaws.com/xofalepelala/lunajoku.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb8e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xFB8E 5488 bytes
SHA-256: aaca3b8584abafd8402c086676242c9322590657269c6416d67cee9ad9923698
font_01_sfnt_off00010dfa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10DFA 1800 bytes
SHA-256: a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
font_02_sfnt_off00011687.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11687 11536 bytes
SHA-256: 6e4e79f41700ad5250281a7e8860aed040d389b73f6951f29302cfaf9376270d
font_03_sfnt_off00013bb8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13BB8 4324 bytes
SHA-256: 7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71