Malicious PDF — malware analysis report

Static analysis result for SHA-256 49c11ae73f73dfe2…

MALICIOUS

PDF

74.9 KB Created: 2021-03-16 08:47:54 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c567c3446a7d28d36c38c786bc58b1cc SHA-1: 196dbbf45b515c66e8342129628e177e2a94f915 SHA-256: 49c11ae73f73dfe2487f0c744b9b26e844c78bad535408fa3df7da92d7dd7de0
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a phishing or trojan threat. It contains a large number of external links, a common technique for SEO spam or directing users to malicious sites. While no scripts were explicitly extracted, the PDF structure and embedded URIs suggest an attempt to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/123?utm_term=oster+versa+pro+performance+blender+reviews
    • https://cdn.sqhk.co/fafaviwi/PidDGHt/31593199728.pdf
    • https://cdn.sqhk.co/gikasiful/zgijbgc/14860797912.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/93886137-3755-438c-87c6-a1e4f3cd99f7/21018472082.pdf
    • https://s3.amazonaws.com/tubukeganuji/58191834719.pdf
    • https://c788b29d-df2d-4d46-9946-349e8cce89b7.filesusr.com/ugd/a9e086_0c99309ce9da4ee09a8abfd48a2593ab.pdf?index=true
    • https://s3.amazonaws.com/fojaxexino/flowers_in_the_attic_2014_full_movie_download_480p.pdf
    • https://uploads.strikinglycdn.com/files/86d4c6eb-404a-4eaa-b2ca-4f8df78bb2b2/71620270263.pdf
    • https://s3.amazonaws.com/xokebore/the_penultimate_peril_audiobook.pdf
    • https://a6132035-7465-4fe4-be4e-2faa96c22dab.filesusr.com/ugd/cf950b_c6a3f97290784fc3902aed2b9680f05c.pdf?index=true
    • https://uploads.strikinglycdn.com/files/3a92bcc9-2cd2-4bbb-9ac2-ad503cec23ec/xofazajugelikidu.pdf
    • https://s3.amazonaws.com/jevelel/telugu_old_audio_naa_songs.pdf
    • https://14535e1a-360a-4d01-a655-fa33e115c80e.filesusr.com/ugd/b222ea_ceb4f6831f824123b824283714955b76.pdf?index=true
    • https://uploads.strikinglycdn.com/files/9f536acf-3699-4050-84cd-bf2ccdc73aa4/besunukodikukome.pdf
    • https://uploads.strikinglycdn.com/files/381a1bab-3531-4115-ab91-67d847ab7515/how_to_scale_measure_in.pdf
    • https://s3.amazonaws.com/lanaladu/the_human_cheek_cell_lab_answer_key.pdf
    • https://uploads.strikinglycdn.com/files/ec9bb115-2203-401a-8f6b-e1ca4feef8df/68992340267.pdf
    • https://uploads.strikinglycdn.com/files/12537928-b572-4afb-afcc-08c36d9b793f/30131108462.pdf
    • https://4c72699b-aa2e-4dc8-8bd5-1a54e8f938a6.filesusr.com/ugd/f3cb45_c786c282545b48de99c19212a119b7dd.pdf?index=true
    • https://uploads.strikinglycdn.com/files/12879ec8-40bc-437b-81b6-ebe881005ac2/58223935119.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e542.bin
5082b7f6663b1c6010304a12727b9796bb6d116d144ba49a5cf621cba12f6b78
pdf-font-stream PDF embedded font (sfnt) at offset 0xE542 5620 bytes
font_01_sfnt_off0000f857.bin
1a32be9bb9d72e56d57655e39c2503872516ba02e6b84a9a2a58262d8d817c66
pdf-font-stream PDF embedded font (sfnt) at offset 0xF857 10580 bytes