Malicious PDF — malware analysis report

Static analysis result for SHA-256 3dbe76a2c02f477d…

MALICIOUS

PDF

91.2 KB Created: 2021-03-29 09:13:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b619ca2cb5db78754f938290483eb204 SHA-1: dca4f97e33ba583226c938b417659ba95bd18555 SHA-256: 3dbe76a2c02f477da45db4a0bba2e357165e03a973e8fa6cfef8720f0bfa3590
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to Weebly and other free hosting services, suggesting a link farm or SEO spam operation. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of a phishing or malware distribution attempt, likely initiated via spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kuzutuzo.ru/award?keyword=taux+d+alphab%25C3%25A9tisation+en+afrique+2020+pdf
    • https://lemorixumo.weebly.com/uploads/1/3/4/7/134748879/9393376.pdf
    • http://bizifemodefi.mygamesonline.org/78088635313.pdf
    • http://gagimubu.mywebcommunity.org/tikefom.pdf
    • https://fatisejodape.weebly.com/uploads/1/3/4/3/134320205/245d291638193.pdf
    • http://giwosoto.sportsontheweb.net/hp_pavilion_dv6000_technical_specifications.pdf
    • https://sugulidan.weebly.com/uploads/1/3/4/5/134508933/kinuxusadaleti.pdf
    • https://sumikoxivabozo.weebly.com/uploads/1/3/3/9/133997645/sagalanuduwuwo_lexogapo_gamivafobuj_tinubesaju.pdf
    • https://penixosifa.weebly.com/uploads/1/3/1/4/131482878/jerov.pdf
    • http://pifafixejizigu.scienceontheweb.net/54429963659.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://db38eef3-7d65-43a4-badd-ba39ed7d9417.filesusr.com/ugd/bd2483_3c06aae0e41b4bb8b9d369a4ff5ee1f3.pdf?index=true
    • https://s3.amazonaws.com/jikopot/babilusixigadefenodexe.pdf
    • https://650c977b-0274-48a2-8498-43c0efc39f4e.filesusr.com/ugd/dbad32_45b151cc787e453a894c3019e6226f40.pdf?index=true
    • http://nabenejajoko.myartsonline.com/60897593913.pdf
    • https://s3.amazonaws.com/zunaduxa/38868325818.pdf
    • https://76ed6b59-b034-43ac-b949-e1c08f76e3cb.filesusr.com/ugd/ee6100_01bf5bafdf4047488c4d428e450e4413.pdf?index=true
    • https://ef9d90ca-5811-4a1c-810e-75bcfae60121.filesusr.com/ugd/a33af7_a81a827cb1d647bbbcc1558fecbf30b8.pdf?index=true
    • https://551f0ad2-75d1-4009-b90b-2f3e3e20230b.filesusr.com/ugd/c2bf0a_dc6455e950814953b578fceb6d5987e9.pdf?index=true
    • https://709e7e89-b264-4d73-b757-064736ed86f1.filesusr.com/ugd/f523c3_fa3f4a8f6e3b49d1a0003bc4b0ad248d.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000108ee.bin
28ced409f9d896115c39e4fae64520d1b5d15d378e4298a1e6ede7be071208d7
pdf-font-stream PDF embedded font (sfnt) at offset 0x108EE 5828 bytes
font_01_sfnt_off00011c76.bin
16d2543b5430a6eb052e3e091a4d087396fba66b0f7893cdb12a4830e642c43e
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C76 13628 bytes
font_02_sfnt_off00014800.bin
313c3940a6f4aae92ceaa1b1a843de6e6f13411355a457aba6e018c383fce54c
pdf-font-stream PDF embedded font (sfnt) at offset 0x14800 16060 bytes