Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ee54d2437d083f6…

MALICIOUS

PDF

67.7 KB Created: 2021-02-23 00:10:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 62f0e2f6789c8fa74182194876fc6472 SHA-1: a11c3ba9b2ece0c7c54100733ef753899ff8200b SHA-256: 3ee54d2437d083f678ceb76c16e7be4164f35f1039d706bb58d66eadbef2f2a1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is identified as malicious by multiple heuristics and an ML classifier, specifically flagging it as a phishing or malicious PDF. It contains a large number of external links, suggesting a link farm or redirection mechanism to potentially malicious sites. While no scripts were explicitly extracted, the PDF structure and embedded URLs indicate an attempt to redirect the user to external content, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://druttle.ru/wix?keyword=peace+like+a+river+chords+hillsong
    • http://supsun-aero.com/69191144666bv050.pdf
    • https://cdn.sqhk.co/bupewazadufa/jjbAicz/escape_the_prison_henry_stickmin_unblocked.pdf
    • https://cdn.sqhk.co/karadirimose/4jfNhbB/idle_human_app_alien.pdf
    • https://cdn.sqhk.co/raxedaninaso/lhiihUt/state_capitalism_meaning_in_english.pdf
    • https://cdn-cms.f-static.net/uploads/4421329/normal_6019a29d27f0c.pdf
    • http://anyita.space/comfort_zone_heater_user_manualam5wq.pdf
    • https://cdn.sqhk.co/dediwifime/kieaHha/ligumopalidavo.pdf
    • http://herss.space/concurrence_pure_et_parfaite_exercices_corrigs49jex.pdf
    • https://cdn.sqhk.co/tolononof/LiagPgf/36494595126.pdf
    • https://cdn-cms.f-static.net/uploads/4412396/normal_5fe7d6e77b6a7.pdf
    • https://cdn.sqhk.co/xakurusuk/CYAhfhd/95414707227.pdf
    • http://monoga.space/a_composio_gentica_de_um_indivduo_recebe_a_denominao_de9klce.pdf
    • https://static.s123-cdn-static.com/uploads/4414489/normal_60078daece57c.pdf
    • https://static.s123-cdn-static.com/uploads/4445340/normal_6000f3158a99e.pdf
    • https://jizoneva.weebly.com/uploads/1/3/0/7/130738725/zijaxafu.pdf
    • http://twoup-viktoria.online/banokusigigenukipezutar31nb6.pdf
    • https://cdn.sqhk.co/lezebulodiw/CRoiijg/81559579278.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cbd2.bin
a37d7c5002fdd68a787324045e930981254104ecb51943e48bd276c22161902c
pdf-font-stream PDF embedded font (sfnt) at offset 0xCBD2 5328 bytes
font_01_sfnt_off0000ddee.bin
ea8623115539a9f2527d33f0e7d5f0c07e7dfc84ed44a9ebfca837c062727dc8
pdf-font-stream PDF embedded font (sfnt) at offset 0xDDEE 10880 bytes