Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d9a63eb38d34653…

MALICIOUS

PDF

88.2 KB Created: 2021-03-17 21:48:43 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 196805e577dfb35df1d8e93557222bf9 SHA-1: 36e1a19d552510ced6d149ccf7e6272d9bdb19fd SHA-256: 3d9a63eb38d34653e6e3eebc9fb9ee9356911dd29919cdb90312a6f6d10a37cc
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to suspicious domains, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of a malicious document designed to redirect users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=administrasi+tes+cfit+pdf
    • https://koponabunabo.weebly.com/uploads/1/3/4/5/134520941/5547331.pdf
    • https://meligobuv.weebly.com/uploads/1/3/1/0/131070858/resezir_katotikejixux_latejimiwabelib_dufuze.pdf
    • https://zolegezuboz.weebly.com/uploads/1/3/4/4/134462972/reboxemedorevojepe.pdf
    • http://shopyou.online/upbte_revaluation_form_2019_last_dateo5qe5.pdf
    • https://nomukemometikuf.weebly.com/uploads/1/3/1/4/131483138/571de2f43.pdf
    • https://leloturopuroka.weebly.com/uploads/1/3/5/9/135956930/69dfecc0.pdf
    • http://minomesiguziv.22web.org/diretalapememijupezo.pdf
    • https://kosonijuzar.weebly.com/uploads/1/3/5/9/135974682/xopafa.pdf
    • https://sabumamopadav.weebly.com/uploads/1/3/5/9/135957329/ruvomusasosa_tosabogadukud_metesuzalajize.pdf
    • https://fuvapevamasazu.weebly.com/uploads/1/3/4/5/134507747/834282.pdf
    • http://hurricane1.space/antifungal_susceptibility_testing_methods15ggs.pdf
    • http://satomupudogoni.22web.org/kagulabimexafisanosot.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://pavasokunise.epizy.com/roadmap_powerpoint_template_free.pdf
    • https://s3.amazonaws.com/wupiwupiwot/section_21_notice_to_tenant_template.pdf
    • http://xesidif.epizy.com/electromagnetic_radiation_readworks_answer_key.pdf
    • https://s3.amazonaws.com/jemazejodep/73607861811.pdf
    • https://s3.amazonaws.com/xuvamuba/twinkle_twinkle_little_star_sheet_music.pdf
    • https://s3.amazonaws.com/petuzutemixuvod/bank_1_catalytic_converter_nissan_maxima.pdf
    • https://s3.amazonaws.com/jesidofefe/wapet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000fb9e.bin
4c5040e63d4a1ca090516a99708c31d2cee868388977a1a54853ca7b61894b07
pdf-font-stream PDF embedded font (sfnt) at offset 0xFB9E 5260 bytes
font_01_sfnt_off00010d62.bin
04a1510cf805ba74aa14cb8cf5c199ad30526fcabe134d006cb18ed56de43d65
pdf-font-stream PDF embedded font (sfnt) at offset 0x10D62 2540 bytes
font_02_sfnt_off00011808.bin
c890b07076889780a5f1a25d4d58e0985d740d6c4ad311095aec865b8fa19018
pdf-font-stream PDF embedded font (sfnt) at offset 0x11808 11008 bytes
font_03_sfnt_off00013daf.bin
4c01831bdfffbafff55fd55c88415eb2201da44b622d6ec769a15ea8bc50db3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x13DAF 16352 bytes