Malicious PDF — malware analysis report

Static analysis result for SHA-256 4943c2473d85dbcb…

MALICIOUS

PDF

83.0 KB Created: 2021-06-03 16:36:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4564b0c1cb2da0a070b01777bd2c4e5 SHA-1: acc6010084b916fd1a30781c789653cf48f87ae2 SHA-256: 4943c2473d85dbcbb1c1b6e8998e646d5b35f6a9f5358e6f66aa87ec2bbc40ff
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many of which are SEO-optimized, suggesting a link farm or phishing attempt. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or distributing unwanted content. No scripts were extracted, but the PDF structure itself is used to facilitate the malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://huntic.ru/pbw?utm_term=how+to+adjust+time+on+casio+g+shock+3230
    • https://lulipexo.weebly.com/uploads/1/3/5/2/135294167/58fcf730.pdf
    • https://bedeliwukaror.weebly.com/uploads/1/3/4/5/134512578/zugozulotedafolakuz.pdf
    • https://cdn-cms.f-static.net/uploads/4424025/normal_602ab3cc03a46.pdf
    • https://static.s123-cdn-static.com/uploads/4481684/normal_5ffdfc739e9e3.pdf
    • https://cdn-cms.f-static.net/uploads/4494138/normal_5fdb1f926732b.pdf
    • https://cdn-cms.f-static.net/uploads/4445115/normal_6031bc4369357.pdf
    • https://static.s123-cdn-static-d.com/uploads/4377647/normal_60b59f6514400.pdf
    • https://cdn-cms.f-static.net/uploads/4380088/normal_6041860debc2a.pdf
    • https://static.s123-cdn-static.com/uploads/4490370/normal_5fc7aa31233cc.pdf
    • https://cdn-cms.f-static.net/uploads/4499002/normal_6035703d4d847.pdf
    • https://netodidomaxamoz.weebly.com/uploads/1/3/4/3/134311991/3154334.pdf
    • https://static.s123-cdn-static.com/uploads/4415080/normal_5fdebd6e82798.pdf
    • https://cdn-cms.f-static.net/uploads/4404112/normal_6033e04402a5b.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/8bfde185-bd02-496d-8503-3d4aeb68b719/excel_spreadsheet_formula_percentage_difference_between_two_numbers.pdf
    • http://sozakuvepar.pbworks.com/w/file/fetch/144518160/what_is_the_story_all_about_keesh.pdf
    • https://uploads.strikinglycdn.com/files/8cc3a1f5-8bfe-4867-8559-4cc66112de81/xewigekiwevaduxejopugazi.pdf
    • https://uploads.strikinglycdn.com/files/e9e92c6e-fd2d-42d1-aabd-a88b8bd3d097/the_boy_in_the_striped_pajamas_chapter_1-6_summary.pdf
    • https://uploads.strikinglycdn.com/files/c2932ede-9dfb-4acc-88ad-8008eb54b2b0/75611682753.pdf
    • https://uploads.strikinglycdn.com/files/00843dfa-0a79-480f-a0f7-043ddea73454/fejonujiwe.pdf
    • http://dimutojopog.pbworks.com/w/file/fetch/144443424/77031079749.pdf
    • https://uploads.strikinglycdn.com/files/00b20288-3b33-4993-bd20-02e4850e1fdb/semerapubovulabazolek.pdf
    • https://uploads.strikinglycdn.com/files/76e3c25c-5cfd-4457-b09a-7b736f7a42d7/16387366847.pdf
    • http://gamaxidad.pbworks.com/f/zuguxip.pdf
    • https://uploads.strikinglycdn.com/files/927a214e-1685-407c-ac4c-6591a95db2f5/51320100085.pdf
    • https://uploads.strikinglycdn.com/files/1506189c-873a-4705-ba15-808fd43a6792/how_to_teach_a_furby_to_talk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000103a0.bin
3184f3db70fb4229a7d2f75cf2f777899ae6fbfaf18c7808fa0d5dd47e7457ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x103A0 5856 bytes
font_01_sfnt_off00011783.bin
15097c66889e33572a685c00df08b96d4d8f3a4864a56be72fe8739ccb8714fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x11783 11416 bytes