Malicious PDF — malware analysis report

Static analysis result for SHA-256 30e8cd90eb8b004c…

MALICIOUS

PDF

68.0 KB Created: 2021-06-04 09:35:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8a15b8685ddb348dad79ff3418f9104e SHA-1: 74a934f30cd7c0c73e19452b8c0db2fe1459dbad SHA-256: 30e8cd90eb8b004c7cff57ecb7250dc25ebe7ddb8004eaf68a31317c60161349
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are to PDF files, suggesting a link farm or phishing attempt. The ClamAV detection and ML classifier indicate malicious intent, likely related to phishing or distributing further malware. No scripts were extracted, but the PDF structure itself is indicative of malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9754

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://laborke.ru/pbw?utm_term=my+singing+monsters+clamble+likes
    • https://demujerifusa.weebly.com/uploads/1/3/1/4/131437649/xatug.pdf
    • https://mabaxezo.weebly.com/uploads/1/3/4/7/134766945/b017d2f6ae0.pdf
    • https://zomipawir.weebly.com/uploads/1/3/4/8/134899005/7599517.pdf
    • https://tagopudul.weebly.com/uploads/1/3/5/3/135392217/4902488.pdf
    • https://kejazomunago.weebly.com/uploads/1/3/0/7/130776678/2543883.pdf
    • https://fotobuwab.weebly.com/uploads/1/3/4/3/134368258/b28850420cb9.pdf
    • https://juleverut.weebly.com/uploads/1/3/4/4/134488806/zosebuxu_vetat_zavabizejegado.pdf
    • https://zafivagofe.weebly.com/uploads/1/3/6/0/136011523/favesakiwu_fekivubone.pdf
    • https://lidisujuv.weebly.com/uploads/1/3/4/5/134515282/bovubukazofezut.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/2a11a1e7-bd26-4e68-a7c3-b11d0c05a1d2/6156725594.pdf
    • http://visetululiv.pbworks.com/w/file/fetch/144422265/modo_de_produccion_primitiva_caracteristicas.pdf
    • http://jujirafamena.pbworks.com/w/file/fetch/144453807/fenub.pdf
    • https://uploads.strikinglycdn.com/files/1feae18c-afd6-4efb-9f8b-08b415b32c00/sezufefijelojitumiza.pdf
    • https://uploads.strikinglycdn.com/files/e587a1cf-75dd-4f60-837a-a13664235d0d/what_is_the_setting_of_ps_i_still_love_you.pdf
    • http://mifimoruzuwo.pbworks.com/f/46404145360.pdf
    • http://zepupifob.pbworks.com/w/file/fetch/144423819/7170242773.pdf
    • http://pefagisunel.pbworks.com/f/yes_virginia_there_is_a_santa_claus_1991_download.pdf
    • http://sozakuvepar.pbworks.com/f/gasibimeb.pdf
    • http://didaneguk.pbworks.com/w/file/fetch/144427413/41497457766.pdf
    • https://uploads.strikinglycdn.com/files/80cb9877-e851-4dc3-81b4-5004cea21173/samudolopewe.pdf
    • http://lulimogosan.pbworks.com/f/how_to_evolve_riolu_brick_bronze.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d9d2.bin
1855d21bc9c908bae71851a7c34aec98d9cc4ce275f31a5ab6f9c252cfefec18
pdf-font-stream PDF embedded font (sfnt) at offset 0xD9D2 5432 bytes
font_01_sfnt_off0000ec51.bin
c48cac226199dc812111308b738b243d5982b305750fe97375d927125e77a534
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC51 11020 bytes