Malicious PDF — malware analysis report

Static analysis result for SHA-256 4468fcab3daa9b65…

MALICIOUS

PDF

82.2 KB Created: 2021-03-20 18:43:51 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9a547251a0b056edf51b33e50a4fe920 SHA-1: 16a0f81054be1a591fed5ab488682bf390247cd0 SHA-256: 4468fcab3daa9b65d9434dbece41bbb9c5fc024673cdb32ded1795420bae7697
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file that contains numerous external links, a common technique for SEO spam or phishing campaigns. The ClamAV detection and ML classifier strongly indicate maliciousness. The presence of embedded URLs suggests an attempt to redirect the user to potentially harmful external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/wix?keyword=7th+grade+geography+curriculum
    • https://gotizede.weebly.com/uploads/1/3/2/6/132695714/fifozixuvil.pdf
    • https://jifefovemerozix.weebly.com/uploads/1/3/4/4/134444698/zadikizowitikax.pdf
    • http://lutefadeba.scienceontheweb.net/26932489172.pdf
    • http://famozosivupiwij.sportsontheweb.net/43848968304.pdf
    • https://cdn-cms.f-static.net/uploads/4444853/normal_6034573de2f13.pdf
    • https://minawitagolufu.weebly.com/uploads/1/3/5/3/135312922/5ec18f692e7611.pdf
    • https://static.s123-cdn-static.com/uploads/4464521/normal_5fd08d907bb88.pdf
    • https://static.s123-cdn-static.com/uploads/4390680/normal_6002af06a88c0.pdf
    • https://static.s123-cdn-static.com/uploads/4487194/normal_6006d9f11fd11.pdf
    • http://xilibinebosapeg.mywebcommunity.org/tipos_de_asientos_contables.pdf
    • http://goladelexugezi.sportsontheweb.net/blessed_assurance_free.pdf
    • https://muxilakenakujud.weebly.com/uploads/1/3/4/0/134012833/dixuripeguvuve.pdf
    • http://rufawefojag.sportsontheweb.net/board_of_revenue_odisha_cuttack_departmental_exam_result_2020.pdf
    • https://galebekamabe.weebly.com/uploads/1/3/4/3/134305591/nuxelen_fovovuzupemejak_nubasifipupuga.pdf
    • https://cdn-cms.f-static.net/uploads/4416321/normal_5fd7e7122d7d7.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/rewepalazamiso/18462924952.pdf
    • https://s3.amazonaws.com/tuxenipup/78799079138.pdf
    • http://jutagejefutix.atwebpages.com/abcesso_dentrio.pdf
    • https://s3.amazonaws.com/daraniwekamidir/estudios_epidemiologicos_experimentales.pdf
    • https://s3.amazonaws.com/posaxugidut/kepetu.pdf
    • https://s3.amazonaws.com/sazixipame/73787820036.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f5d1.bin
49fb37e2eaad794c2231f2d6e99f7c7e17f7890e2305e50b34f7f6af16087ca5
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5D1 5172 bytes
font_01_sfnt_off00010777.bin
c6638aefd2fe7dca102048b231650629d9786e3d2ca6b774975ad7aeec13a2c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x10777 10696 bytes
font_02_sfnt_off00012bc6.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x12BC6 4324 bytes