Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f2b8d16c3347d13…

MALICIOUS

PDF

74.1 KB Created: 2021-03-20 19:12:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 630a413687bc33b67ad671c9532e6eaa SHA-1: 6d108dc291e62f7aed85013c2d3544cb716fb34d SHA-256: 3f2b8d16c3347d1356766ad18a52ea4cc495955ab69470bb22eb98d387a891c1
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a significant number of external links, identified as a link farm, suggesting a malicious intent to redirect users to potentially harmful sites. The ClamAV detection and ML classifier strongly indicate malicious content, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URLs point towards an attempt to exploit users via malicious web content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/strik?utm_term=in+a+split+second+thesaurus
    • https://valutakawewa.weebly.com/uploads/1/3/1/3/131378791/dixufotaw.pdf
    • https://jizimixu.weebly.com/uploads/1/3/4/0/134095846/1922280.pdf
    • https://cdn-cms.f-static.net/uploads/4374703/normal_600b77de3659e.pdf
    • http://form-lnstagramcopyrightservices.com/environmental_conservation_officer_study_guidehfge1.pdf
    • http://gisoboxizaza.mygamesonline.org/javascript_absolute_position_of_element.pdf
    • https://static.s123-cdn-static.com/uploads/4426974/normal_5fe52900a4fd7.pdf
    • https://static.s123-cdn-static.com/uploads/4444098/normal_5fc64e14c409d.pdf
    • https://zeduwekikozive.weebly.com/uploads/1/3/6/0/136050246/32bb0530a.pdf
    • https://jetebudatupa.weebly.com/uploads/1/3/4/7/134748577/08c23b7cb3c3.pdf
    • http://makedctl.site/59675486080m287e.pdf
    • http://leledup.mypressonline.com/how_to_clean_air_filter_in_lawn_mower.pdf
    • https://levukuwaxumofet.weebly.com/uploads/1/3/1/3/131383949/203bb9c.pdf
    • http://taforojujutusig.mygamesonline.org/troy_bilt_lawn_mower_belt_replacement.pdf
    • https://felixitu.weebly.com/uploads/1/3/4/0/134012625/gusatanonefesus-zidogasatodadod-wagifunutil.pdf
    • http://jixewelo.scienceontheweb.net/everlast_activity_tracker_watch.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://mekasesajiw.onlinewebshop.net/97164842532.pdf
    • https://s3.amazonaws.com/zosevid/bonemerefebepa.pdf
    • https://s3.amazonaws.com/lovomijelun/reponoleperorage.pdf
    • https://s3.amazonaws.com/tikoweravisixu/badland_2_apk4fun.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e282.bin
512bac9631b4e620dee1d1e64448009d8b7d8a622a2442b46af0b3e8119d11de
pdf-font-stream PDF embedded font (sfnt) at offset 0xE282 5100 bytes
font_01_sfnt_off0000f3cb.bin
087d75161c8239297580b69c98d8b003a8780775c80186452d6a4ae453151438
pdf-font-stream PDF embedded font (sfnt) at offset 0xF3CB 11756 bytes