Malicious PDF — malware analysis report

Static analysis result for SHA-256 4911f04734058ace…

MALICIOUS

PDF

81.5 KB Created: 2021-03-27 17:54:49 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d9546122ec7b510478e201361f83dbed SHA-1: ed9ba2c114caa6632ed7efdf246aa2d2d0cdce95 SHA-256: 4911f04734058ace04bd73028af2ed270834e5a3f7adf779c0df3475f57ad9ac
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, a technique often used for SEO farms or to redirect users to phishing sites. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as 'Pdf.Phishing.Trojan'. While no scripts were directly extracted, the PDF structure and numerous URLs suggest it's designed to lead users to malicious content, potentially a phishing page or a download for further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://botokaw.ru/strik?utm_term=is+storm+on+the+island+about+the+troubles
    • https://cdn.sqhk.co/tatogevi/wjaiiSq/fawuga.pdf
    • http://lnstagramverifiedsbadgesforms.com/chamatkar_film_videow4w0k.pdf
    • http://tizezs.xyz/nofivesibopinisotuminibol5yty.pdf
    • https://cdn.sqhk.co/sezogitov/bhdkhag/siberian_cat_breeders_florida.pdf
    • http://excschool.ru/liwobarodewazukorivuxezusacjv6.pdf
    • https://cdn.sqhk.co/fasisela/hhKjcih/jezoxugawu.pdf
    • https://cdn.sqhk.co/gonolesuzam/id3G9Rm/zeraki_learning_apk_download_for_pc.pdf
    • https://cdn.sqhk.co/govazofaj/ghjifjb/shotgun_machine_gun_cheats_for_gunblood.pdf
    • http://bloomwithdeanna.com/dopovutobazifewadzw3.pdf
    • https://weludabaner.weebly.com/uploads/1/3/4/8/134854782/4086f5f2.pdf
    • https://cdn.sqhk.co/vawikepaf/JSgjiiH/zazedopejama.pdf
    • http://meetlait.pro/jump_force_character_pass_2_switchg605n.pdf
    • https://lejegibovijidup.weebly.com/uploads/1/3/1/4/131438293/9594292.pdf
    • https://cdn.sqhk.co/zamokaxu/7hdifhg/60898643088.pdf
    • https://cdn.sqhk.co/nurofiwele/jeuyFlZ/38808527530.pdf
    • http://opssmall.space/academic_paper_template_latex5ez40.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f444.bin
2b4caf0d0ad2c2584d6817d93e12199cd60818f1424d0b4798eee2adcb744147
pdf-font-stream PDF embedded font (sfnt) at offset 0xF444 5024 bytes
font_01_sfnt_off0001050f.bin
a55908cac424b2831f82fa5aacc56d7ed5598a59b24b60024a2f59b5dd0c8e89
pdf-font-stream PDF embedded font (sfnt) at offset 0x1050F 10544 bytes
font_02_sfnt_off000128e3.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x128E3 4324 bytes