Malicious PDF — malware analysis report

Static analysis result for SHA-256 36fc503e8512f869…

MALICIOUS

PDF

75.7 KB Created: 2021-03-18 12:04:35 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f9b4702185853f13457e5da1a548ca03 SHA-1: 5cdaaf34c81d83a5066158af6aad636f517bbab1 SHA-256: 36fc503e8512f8698871ab4a49cb5c01bb18f71d4fb86fbdf6ccac7e4dc8a275
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing or SEO link farm attack. It contains numerous external links, with a primary link to 'ponafet.ru' and a large number of links to Weebly-hosted PDF files, suggesting an attempt to manipulate search engine results or redirect users to malicious content. No scripts were extracted, but the PDF structure and numerous external links strongly indicate a malicious intent to redirect users.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=hatchet+survival+guide+project
    • https://wulaludotesi.weebly.com/uploads/1/3/0/9/130969185/2734971.pdf
    • https://berebexamoleti.weebly.com/uploads/1/3/1/3/131384136/6859039.pdf
    • http://study-english-04.space/xelolorukuqnbvy.pdf
    • https://vigenuwotefi.weebly.com/uploads/1/3/4/0/134012497/4553619.pdf
    • http://itclick.pro/51881109291evqb5.pdf
    • https://guzepebizosi.weebly.com/uploads/1/3/4/8/134880367/7764b4d10f56c33.pdf
    • https://tunozuranoba.weebly.com/uploads/1/3/5/3/135316660/e0299.pdf
    • http://alisaborodaenko.design/70389265698atb5g.pdf
    • https://gefidiwe.weebly.com/uploads/1/3/0/7/130738847/2115550.pdf
    • https://xifanelisiwokof.weebly.com/uploads/1/3/0/8/130874433/76f0a0250cc.pdf
    • http://sayfelengs.space/gozijumixiwuxutijodown9me.pdf
    • http://handler-autoscout24.com/vitekukefakerinubsbmjx.pdf
    • http://help-verification.com/cute_halloween_costumes_for_teenage_girl_pinterestlniw4.pdf
    • https://wumefabifu.weebly.com/uploads/1/3/4/8/134888429/zaramuxukowamexewuxu.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/falufusu/ambassadors_of_christ_videos_songs.pdf
    • https://s3.amazonaws.com/sajatofubote/uri_the_surgical_strike_trailer_mp4.pdf
    • https://bac325b5-3710-4a60-ba01-c1ac5e8a7650.filesusr.com/ugd/c111de_efbd5a3c7c274aba8c42c7441d1abdc6.pdf?index=true
    • https://16012499-1299-48b0-8cdd-5f23a7749958.filesusr.com/ugd/fafc38_75affc7d591340748021a1481c0a8a66.pdf?index=true
    • https://7c9e9c40-2b96-4f88-8065-b5ff5e495659.filesusr.com/ugd/3bfcae_95d662197fa24384b00084bf316e70d8.pdf?index=true
    • https://f405dec1-7f90-4f4c-a861-5286f67d0127.filesusr.com/ugd/ab922d_30a2ea977a184fa2b9996bb3ca775fdb.pdf?index=true
    • https://c18d9829-3add-4afa-bc87-35007fe3998a.filesusr.com/ugd/70c1ec_a6cde0c546e94521a5b1fd48a163b3b3.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e7a2.bin
a01c076dfcf37760c8c967838154c13743e4cb14316c24f18748aa7139a5fa91
pdf-font-stream PDF embedded font (sfnt) at offset 0xE7A2 5432 bytes
font_01_sfnt_off0000fa1f.bin
528056083dfdbe0eadd96085c779c01614574dba34172ee873d7fa7bdadf9fd1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA1F 10972 bytes