Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c1531f2a5fe17d7…

MALICIOUS

PDF

91.2 KB Created: 2021-03-18 08:43:55 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 380288ddaa3b74b8533c25c94e081483 SHA-1: 2cc104e0a1e805dc18695e571246ab0baa27bfd1 SHA-256: 3c1531f2a5fe17d7063a93e42ca26eb1d9562d78b3f21f137cd8558c4733f6ae
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to Weebly and other free hosting services, suggesting a link farm or phishing campaign. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a phishing or malware distribution lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9989

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://soxebez.ru/wix?keyword=navy+maritime+claims+reference+manual
    • https://zizovotitimojuv.weebly.com/uploads/1/3/2/7/132712514/sivaludibex_ditadedu_tipaju_zebepo.pdf
    • http://woronari.getenjoyment.net/what_is_dependency_theory.pdf
    • https://degegoza.weebly.com/uploads/1/3/0/8/130873855/4503221.pdf
    • https://cdn.sqhk.co/siwowoso/c2ggRQ6/bheema_tamil_movie_songs_isaimini.pdf
    • http://xomutukegadoj.mypressonline.com/alphabet_coloring_worksheet.pdf
    • https://rivakevalitute.weebly.com/uploads/1/3/0/8/130813818/rogosas-koxubi-bupoxunap-bezesujejusamuw.pdf
    • https://cdn.sqhk.co/zaviresodew/CiiLhfF/49066021779.pdf
    • https://cdn.sqhk.co/junikesiza/heWWhdf/exit_interview_form_template.pdf
    • https://cdn.sqhk.co/xurajalijok/ijnPZgi/xadiduku.pdf
    • http://likedizar.medianewsonline.com/maytag_quiet_series_300_no_water.pdf
    • https://cdn.sqhk.co/vogoxaginoje/fGtiew8/bijimorugufe.pdf
    • http://nowukusox.mypressonline.com/how_to_fix_samsung_galaxy_tab_3_battery_drain.pdf
    • https://lefeputabewaro.weebly.com/uploads/1/3/2/6/132695219/jimazefuvet.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/0ac95cf0-a951-43fe-955c-18937c753d90/wivekorulupefav.pdf
    • https://s3.amazonaws.com/gedesisumi/aire_totale_d_un_cylindre_formule.pdf
    • https://s3.amazonaws.com/donukadizolin/made_easy_mechanical_engg_handbook.pdf
    • https://uploads.strikinglycdn.com/files/d44a4519-b8d9-43d2-af84-f68a670f9629/serelununo.pdf
    • https://uploads.strikinglycdn.com/files/0003703d-d2c2-4ff6-9116-2266602ad217/burger_king_fries_nutritional_value.pdf
    • https://uploads.strikinglycdn.com/files/3486fcb3-3b25-44b1-a7ce-569eec62000c/godrej_refrigerator_models_with_price_list_in_india.pdf
    • https://s3.amazonaws.com/gopuze/balance_sheet_format_as_per_companies_act.pdf
    • https://uploads.strikinglycdn.com/files/d63456c4-538b-45b6-990e-a48e9e14b71a/how_do_i_access_an_old_google_account.pdf
    • https://uploads.strikinglycdn.com/files/bd61752a-7d79-4283-a7e2-c538d080515a/resistance_bands_exercises_for_beginners_legs.pdf
    • https://uploads.strikinglycdn.com/files/b365c9f1-2a20-40c1-a674-2b20b0e96199/42684971562.pdf
    • https://s3.amazonaws.com/fosalizuzu/sales_commission_contract_template_uk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011324.bin
ffb7f5d23d17fcca180c4764eca67e43abaee58853f9d5a3909ce7273b8e731f
pdf-font-stream PDF embedded font (sfnt) at offset 0x11324 5156 bytes
font_01_sfnt_off000124ae.bin
4bce8a497af46ec384784a4e0140cdb6fa8dd6402a09b3c7a9e6dc386bb3f34c
pdf-font-stream PDF embedded font (sfnt) at offset 0x124AE 10636 bytes
font_02_sfnt_off00014917.bin
532315dfdc59b350d447ad91845dd8cc72a836e684f536ab9a4305dc5b53fb8e
pdf-font-stream PDF embedded font (sfnt) at offset 0x14917 16204 bytes