Malicious PDF — malware analysis report

Static analysis result for SHA-256 3415b29229507908…

MALICIOUS

PDF

77.9 KB Created: 2021-04-05 13:53:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7c56d5bb5ad6648f940735271f8fab7a SHA-1: d640fd49b6653f7cf09e27b77d640f2c5f281ce1 SHA-256: 3415b292295079089271ae9b0fb7866bb11a679465be7f7caad0480ee578cfe2
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, characteristic of a link farm or phishing lure, directing users to potentially malicious websites. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware distribution. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic suggest the document is designed to drive traffic to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://nipisod.ru/strik?utm_term=poulan+chainsaw+repair+near+me
    • https://cdn.sqhk.co/lemijexo/RGjageQ/dare_you_viral_video_trends.pdf
    • http://gvidilon.ru/84383214652a7vnz.pdf
    • http://italy-small.space/xosinonelipujoxudulywmgp.pdf
    • https://zebomutob.weebly.com/uploads/1/3/2/6/132696512/b22f926129a4.pdf
    • http://creditinquiry.info/big_little_farmer_game_mod_apkdaqd5.pdf
    • https://cdn.sqhk.co/korokotuduki/ibijp7V/2048_shoot_n_merge_shoot_up_schools.pdf
    • http://trudogoliya.online/chrono_trigger_snes_cartridge_ebay8396n.pdf
    • https://fedebeforejasu.weebly.com/uploads/1/3/4/4/134498020/47e2b24.pdf
    • http://cardioactiveuficiale.site/kozezuvewotogebevepinthasr.pdf
    • https://cdn-cms.f-static.net/uploads/4408336/normal_5fe693b727895.pdf
    • https://cdn.sqhk.co/pumibavi/YidDD9u/tagebejimagifafilaroloku.pdf
    • https://cdn-cms.f-static.net/uploads/4468294/normal_601855b950f91.pdf
    • https://cdn.sqhk.co/rufetuzek/ejcf3ib/real_steel_world_3d_robot_boxing_2.pdf
    • https://punulizi.weebly.com/uploads/1/3/5/9/135957491/valipagijideraramagu.pdf
    • http://iranomics.com/64243248960629cd.pdf
    • https://cdn.sqhk.co/nodujugebi/quPihgf/new_york_city_highlights_tour.pdf
    • https://cdn.sqhk.co/ronofumito/isgcihw/facebook_lite_apk_version_2019.pdf
    • https://cdn.sqhk.co/fenogate/6geAIgc/93149786593.pdf
    • http://leqqurint.online/40958772135s20bd.pdf
    • https://fetavagipiw.weebly.com/uploads/1/3/1/3/131380759/zevagitexejexeruzu.pdf
    • https://betebawaxudu.weebly.com/uploads/1/3/5/3/135388356/lugaximeze.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f03e.bin
5d6d67cf388146e9d5a8bd4f6bd18ec165a186cd0cb7d2c2965e8fbf99084e9a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF03E 5264 bytes
font_01_sfnt_off0001020b.bin
bfcf33f989366ff3ab8c21d91c42e60042f8b760388623d5096d3318acf25ca2
pdf-font-stream PDF embedded font (sfnt) at offset 0x1020B 11948 bytes