Malicious PDF — malware analysis report

Static analysis result for SHA-256 33a6a726ae1caefe…

MALICIOUS

PDF

65.0 KB Created: 2021-06-11 08:56:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b80f0581658a50299d8f424eb104a312 SHA-1: 6eabc3a4b0f060dbbf274db50a8e792373500cea SHA-256: 33a6a726ae1caefe26e3eeb8753b619f8937af0f16eb3720da008530fa9e6289
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which point to PDF files, suggesting a link farm or SEO manipulation tactic. The ClamAV detection and ML classifier indicate malicious intent, likely related to phishing or distributing further malware. No scripts were extracted, but the embedded URLs are the primary indicators of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5155

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://queure.ru/pbw?utm_term=atom+to+mole+calculator
    • https://barijenevedi.weebly.com/uploads/1/3/1/4/131438420/66ce6cbac3dcdd.pdf
    • https://static.s123-cdn-static-d.com/uploads/4448343/normal_60b6920a222ce.pdf
    • https://cdn-cms.f-static.net/uploads/4465007/normal_604d95674710f.pdf
    • https://nigepopevoxi.weebly.com/uploads/1/3/4/8/134881291/1680064.pdf
    • https://wedezetepeb.weebly.com/uploads/1/3/4/5/134528952/suravezidise.pdf
    • https://cdn-cms.f-static.net/uploads/4409255/normal_601715672f30d.pdf
    • https://cdn-cms.f-static.net/uploads/4414689/normal_604cccf0ef7ab.pdf
    • https://fogujudusimasob.weebly.com/uploads/1/3/4/7/134713994/vakaditox_lejaxivizar_kewezova_wopomuxosap.pdf
    • https://cdn-cms.f-static.net/uploads/4483873/normal_60ba85b5321e7.pdf
    • https://xasibegofijuga.weebly.com/uploads/1/3/4/7/134731363/suvojujeva.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/3c0b733d-cd26-4767-b1f1-231680ca5fc9/40750626154.pdf
    • http://bokibagaror.pbworks.com/f/how_to_use_rowenta_xcel_steamer.pdf
    • http://mevuteled.pbworks.com/w/file/fetch/144546288/ncert_solutions_for_class_11_biology_free_download_in_hindi.pdf
    • http://zajozote.pbworks.com/f/38497933804.pdf
    • http://degenazi.pbworks.com/w/file/fetch/144456813/electronics_principles_and_applications.pdf
    • https://uploads.strikinglycdn.com/files/b824e454-9a55-4b7d-ba49-19cb24216525/boxariparifotuge.pdf
    • http://xedidovetaw.pbworks.com/f/fiche_fraction_cm1.pdf
    • https://uploads.strikinglycdn.com/files/9312029b-d1b5-4ca9-a8ed-e06520897ba4/a_thousand_splendid_suns_analysis_questions.pdf
    • https://uploads.strikinglycdn.com/files/d0f7535e-5934-4720-9844-8c14dc5ae2c3/why_do_smoke_detectors_go_off_then_stop.pdf
    • http://nolumemonip.pbworks.com/f/complete_book_of_baths_by_robert_laremy.pdf
    • http://favixose.pbworks.com/w/file/fetch/144553200/how_to_reset_samsung_galaxy_tab_3_to_factory_settings.pdf
    • https://uploads.strikinglycdn.com/files/e0ea30c6-4594-413a-9ee4-040bc908a5a4/the_keto_guido_cookbook_free_download.pdf
    • https://uploads.strikinglycdn.com/files/eb94cfc6-8d85-48e8-9075-9c9efbbf4b8b/letawowenotewoxasufo.pdf
    • https://uploads.strikinglycdn.com/files/0ec9037a-2905-418d-97a8-a3b5d217eb05/flo_pro_6.4_egr_delete_instructions.pdf
    • https://uploads.strikinglycdn.com/files/be011753-aadc-406d-9d4a-b09de66f6a56/is_halo_fall_of_reach_canon.pdf
    • http://gitixofipoxu.pbworks.com/w/file/fetch/144554115/ball_bricks_breaker_3_mod_apk.pdf
    • http://bezawagiga.pbworks.com/f/cch_xa_ti_khon_twitter_khi_b_nh_ch.pdf
    • http://sijomirurefi.pbworks.com/f/mortal_kombat_x_johnny_cage_moves.pdf
    • https://uploads.strikinglycdn.com/files/033cfd49-8f2c-40bc-8064-c84a362fb7c6/mapa_zonas_de_riesgo_cdmx.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e87c.bin
be52c5b40c37b17a0d08747c154fc98a066d86149cea908551779ce1a3f17a3b
pdf-font-stream PDF embedded font (sfnt) at offset 0xE87C 4756 bytes