Malicious PDF — malware analysis report

Static analysis result for SHA-256 36d40502b0db46fa…

MALICIOUS

PDF

103.3 KB Created: 2021-03-15 18:02:53 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b6b22ba2eb3c464ba55c72bf8df88fcb SHA-1: 7a87b17671e064b8919b4689b03e0b888c1e289e SHA-256: 36d40502b0db46fa32b3234e0d5b23c4e1571451c4da3285789e6cc2fbb030a1
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are dynamically generated and point to PDF files, suggesting a link farm or SEO poisoning tactic. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and heuristic firings point towards a malicious document designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9959

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/award?keyword=biology+notes+for+ssc+exam+pdf
    • https://cdn.sqhk.co/gorubabor/Onnichg/romancing_saga_2_dantarg_3rd_form.pdf
    • https://cdn.sqhk.co/porekige/lyZAsDc/watuzajiniva.pdf
    • https://xasigali.weebly.com/uploads/1/3/4/3/134363336/c807a.pdf
    • https://dibasipelop.weebly.com/uploads/1/3/0/7/130738559/paxasuluvupe.pdf
    • https://vedexojofidas.weebly.com/uploads/1/3/4/5/134581268/wanapoladenip_xelitutu_gurirere.pdf
    • https://bololadagulit.weebly.com/uploads/1/3/5/3/135348095/0cb8cb902413469.pdf
    • https://farurepakal.weebly.com/uploads/1/3/5/3/135318469/f29e9.pdf
    • https://felekiki.weebly.com/uploads/1/3/4/6/134689652/2926199.pdf
    • https://cdn.sqhk.co/pibusupi/alRhbkp/benod.pdf
    • https://jipofaxinevafud.weebly.com/uploads/1/3/4/3/134350183/gisatomoromupuf.pdf
    • https://mebifexet.weebly.com/uploads/1/3/1/3/131381374/3779526.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • https://uploads.strikinglycdn.com/files/071e2800-b310-41a3-84ed-e386f4d6e311/18921706748.pdf
    • https://uploads.strikinglycdn.com/files/7ad7cbc0-1dd5-4488-bf7e-a5ee8e86d502/thrustmaster_t_flight_hotas_one_joystick_for_xbox_one_and_pc_review.pdf
    • https://1423d76f-a56f-4481-bf87-726e17039346.filesusr.com/ugd/14aee2_838d7527abd948ffb3ba4e1f77cb75cc.pdf?index=true
    • https://s3.amazonaws.com/zuwimadaneb/29778657886.pdf
    • https://70745723-7f4a-4dc7-98be-95bdce43cd82.filesusr.com/ugd/67bae7_d5ffc9f0cf4146f1ae2e1e7b209a659e.pdf?index=true
    • https://s3.amazonaws.com/xapota/12712923607.pdf
    • https://uploads.strikinglycdn.com/files/04e4c938-666f-45a4-8eb3-b9f3d4a10690/bekiguvufifuli.pdf
    • https://uploads.strikinglycdn.com/files/184a7631-2eb1-41de-bfa9-77576c2fb3df/memukafix.pdf
    • https://s3.amazonaws.com/legenapi/maytag_bravos_xl_error_codes_e2_f6.pdf
    • https://29aa9d28-cc9d-45fc-8d86-3718b5881c84.filesusr.com/ugd/74c34a_9b4a2406582e4ac09a5d30d4da2540f2.pdf?index=true
    • https://uploads.strikinglycdn.com/files/1a4f83a9-6a3f-4c06-b5d2-08030582a400/logitech_k400_scroll_not_working.pdf
    • https://ad0d0dbb-669b-46a9-85df-79487014a0f3.filesusr.com/ugd/00d95d_a4979fe70ade4050a729225f1237d138.pdf?index=true
    • https://9d76d0c6-5807-43ac-a2ba-7b4112d1a20a.filesusr.com/ugd/5cd33b_6aff7c6166794b7584ac024d582e31d0.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000100c4.bin
f6b341dde9510f562d606f228692b626abe6873ff06569db3df9a9c89f484177
pdf-font-stream PDF embedded font (sfnt) at offset 0x100C4 5696 bytes
font_01_sfnt_off0001142b.bin
d5ecec3e822993868ba70e247019bcdb656a9fee58d620eb93bc70658e929280
pdf-font-stream PDF embedded font (sfnt) at offset 0x1142B 3720 bytes
font_02_sfnt_off00011f86.bin
cf0d8fb5527eae19401dfc12654250517e7a38e3cc95ac791bee53c0147e1778
pdf-font-stream PDF embedded font (sfnt) at offset 0x11F86 1972 bytes
font_03_sfnt_off000128f9.bin
d0716ccef5f9436bdde700610d16228bf1a4a8fc41edf10c300cb43bf1e2a7f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x128F9 10668 bytes
font_04_sfnt_off00014d90.bin
9e020c854edd9d16e76d4d276d806d6ad9537766fc0f49e31c6b0dee74960295
pdf-font-stream PDF embedded font (sfnt) at offset 0x14D90 16248 bytes
font_05_sfnt_off00016322.bin
213cd0f0cd8665de6f7c936ef10c1d4cc523bdee2c10685830a0ac8b3b3f3c5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x16322 14320 bytes