Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a061651cbf7ed94…

MALICIOUS

PDF

82.7 KB Created: 2021-03-27 20:17:17 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 27911e228e32b0ddfd0a20cc2f83e95a SHA-1: 63eed7fabdd523c171d323569a9baed72b7532b9 SHA-256: 4a061651cbf7ed94a70d8944116dbe06af91f114be5067887f42855a2c48c28f
164 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, with a critical heuristic flagging it as a 'PDF_SEO_LINK_FARM'. The document body, though truncated and obfuscated, suggests a lure related to document receipt. The presence of multiple unknown URLs indicates a high likelihood of these being used to host or redirect to malicious content, likely a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://vilenefex.ru/wix?keyword=acknowledgement+letter+of+receipt+of+documents
    • http://komaxinatobofe.medianewsonline.com/vujav.pdf
    • http://nejupike.mygamesonline.org/entropia_e_a_segunda_lei_da_termodinmica.pdf
    • http://nakotigolajeg.scienceontheweb.net/40063905426.pdf
    • http://tafuxasomup.getenjoyment.net/25773100174.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ebe4fa10-ee08-49d9-82bb-d991111faa74/64170475863.pdf
    • https://uploads.strikinglycdn.com/files/ec2a8d3e-214b-444e-a218-d61e334ff589/jazzy_select_gt_parts.pdf
    • https://8d59741e-369e-44be-b01e-8fbcb09d2d01.filesusr.com/ugd/7cefa9_201bd2ee15274cdcb704f5dae6e4b47f.pdf?index=true
    • https://s3.amazonaws.com/lawakux/43974459974.pdf
    • http://mekasesajiw.onlinewebshop.net/44861437159.pdf
    • https://uploads.strikinglycdn.com/files/2e8b384c-0498-4fb3-95e7-e69727171fe7/armor_of_god_prayer_for_husband.pdf
    • http://pazobojar.rf.gd/catia_v5_freestyle_tutorial.pdf
    • https://s3.amazonaws.com/fifomi/fajidikivunojalora.pdf
    • https://uploads.strikinglycdn.com/files/e2a12348-f870-4859-9ffb-5408b8813b2b/is_vinegar_a_weak_electrolyte.pdf
    • https://cb71deac-5427-4a11-aec2-6feec017c243.filesusr.com/ugd/4cd983_ea7d04292ed645a2bb7b511c8ba7313c.pdf?index=true
    • https://4a0f17ac-6ce6-4c05-9546-25c48d39d9f7.filesusr.com/ugd/cd79e3_8c2cf20c0bd94d3aac47d91b7ae01f70.pdf?index=true
    • https://uploads.strikinglycdn.com/files/a4b02af8-83a5-4391-905c-6a60d1df8cdc/hague_watermax_home_not_found.pdf
    • https://748e62c5-a849-4dff-87e7-3b5f74cb3522.filesusr.com/ugd/0df896_757bbfdc3c4740b09af3b2a6c773c842.pdf?index=true
    • https://4ad55601-b8ab-4ae0-bc0e-e90069072326.filesusr.com/ugd/3aca14_f4d5bb8670114c1cb0c49b6b62551bb5.pdf?index=true
    • https://s3.amazonaws.com/ladojenefe/mafuzowafegusixatesinuvo.pdf
    • https://uploads.strikinglycdn.com/files/b169c983-3117-43bd-a47b-6cfde7b76f69/trigonometry_worksheet_answers.pdf
    • http://mujozigimak.rf.gd/small_compress.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000108fb.bin
a0ca1eeeacc38ff25f8084d46cc1ca1585978410a8c7e5b1344516fe8542248e
pdf-font-stream PDF embedded font (sfnt) at offset 0x108FB 5408 bytes
font_01_sfnt_off00011b72.bin
4b89566bb5f6689bb261a9ac5cdf1c30cf59bd80f057bf2f1d080baf1cc517fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x11B72 9968 bytes