Malicious PDF — malware analysis report

Static analysis result for SHA-256 3b41ea1c5cb4a214…

MALICIOUS

PDF

98.2 KB Created: 2021-02-24 16:14:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 809448a5a17d46a1997be0bc7764e330 SHA-1: b92cdf53795a19b15bbc4fcf8517b862474a1af6 SHA-256: 3b41ea1c5cb4a21414ca32362834712924e9b711deca0a63c4233d8c87b60d93
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a link farm, with many pointing to S3 buckets and other domains. The ClamAV detection and ML classifier indicate malicious intent, likely related to phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and numerous external URLs suggest an attempt to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7879

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bologen.ru/award?keyword=what+is+the+meaning+of+a+man-at-arms
    • https://fuvapevamasazu.weebly.com/uploads/1/3/4/5/134507747/fcd52b54b2.pdf
    • http://love-cosmetics.shop/7787254671976aqt.pdf
    • http://semengergel.ru/zezelokito8v0et.pdf
    • https://sajofagexureleb.weebly.com/uploads/1/3/4/6/134652103/fewaxafo-jagigifajinis.pdf
    • http://grusha.space/section_5_firearms_act_1968_sentencing_guidelinescua7f.pdf
    • https://cdn.sqhk.co/zururodi/hcEib5c/63988787677.pdf
    • https://cdn.sqhk.co/basinasedu/HR5jjyM/globe_load_top_up_mobile_legends.pdf
    • http://cancandance.org/dogfight_2_hacked_unlimited_health_unblockedvrmvb.pdf
    • https://mefupajudeto.weebly.com/uploads/1/3/4/8/134883840/wokug.pdf
    • https://cdn.sqhk.co/numiwuzuwix/gjahgjc/65827713221.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://www.opentle.org
    • https://s3.amazonaws.com/wixamupelinere/vocal_remover_apk_full.pdf
    • https://s3.amazonaws.com/tedowafomaru/avantage_concurrentiel.pdf
    • https://s3.amazonaws.com/pusori/you_are_old_father_william_answers.pdf
    • https://s3.amazonaws.com/mibiwivanetuj/ad_hoc_wireless_networks_textbook.pdf
    • https://s3.amazonaws.com/tugafebip/bolt_report_alex_malley.pdf
    • http://scripts.sil.org/OFL
    • http://www.gnu.org/licenses/gpl.html

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012173.bin
40ed7a59e93a39a2357a6714e82246a7d8382393c541a7d084f33d2bd6126fa4
pdf-font-stream PDF embedded font (sfnt) at offset 0x12173 5588 bytes
font_01_sfnt_off00013503.bin
326cfdead8d000cb2cb8f27749aec9835bbfc40f63d4ca57c26c6f7b6d370a35
pdf-font-stream PDF embedded font (sfnt) at offset 0x13503 5196 bytes
font_02_sfnt_off00014695.bin
c206ac4eca120f096112d408dff6b33a2f721090936d80486df636e1cd240fde
pdf-font-stream PDF embedded font (sfnt) at offset 0x14695 2656 bytes
font_03_sfnt_off0001519b.bin
3702365b3034b9d7945da23b991b5e2ac3f8bb06d1ba3be7e5ba1b5d8dd48c9f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1519B 2328 bytes
font_04_sfnt_off00015c52.bin
e66bd646ff29f48b94a898642357a1d5295b77faffa0bd70eb77acb4aebc9a97
pdf-font-stream PDF embedded font (sfnt) at offset 0x15C52 2108 bytes
font_05_sfnt_off0001661e.bin
eca62b72654736461a635ba366d09d794777fd95c58152d2b251becdfce657e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1661E 6640 bytes