Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ab10bad1b6afa54…

MALICIOUS

PDF

76.3 KB Created: 2021-03-29 01:06:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f0ab2c345598b4a9f076f39c2f54c9f9 SHA-1: 40bd46c596911382e693352f7c3c450ccde8be5d SHA-256: 4ab10bad1b6afa54aa1a5a6f666116e21ec68471e607d827a4664031ef00769c
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, indicative of a link farm designed to obscure the true destination and potentially host malicious content. ClamAV and ML classifiers flagged this file as malicious, with specific detection for Pdf.Phishing.Trojan. The presence of embedded URLs and the heuristic firing for PDF_SEO_LINK_FARM strongly suggest this document is part of a phishing or malware distribution scheme, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9541

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://leonvi.ru/award?keyword=mean+median+mode+grouped+data+example+problems+pdf
    • https://cdn.sqhk.co/waximanodif/AtFjdwY/looper_jamman_stereo.pdf
    • https://taleputara.weebly.com/uploads/1/3/4/3/134305900/7028350.pdf
    • http://amsidisi.xyz/english_learning_app_offline_free_downloadh5aaa.pdf
    • https://wikabolodaj.weebly.com/uploads/1/3/4/6/134648749/fbc76fc32d11.pdf
    • http://proita.fun/why_has_my_pool_pump_stopped_workingxbuib.pdf
    • https://lepabamun.weebly.com/uploads/1/3/1/6/131636917/3ee7592d.pdf
    • https://cdn.sqhk.co/nimenodeloxa/hhhjDje/carpal_tunnel_syndrome_exercise.pdf
    • https://viworisexefu.weebly.com/uploads/1/3/4/8/134885507/c3065f.pdf
    • https://cdn.sqhk.co/giwumazusew/ijifQv9/digicel_group_jamaica_address.pdf
    • http://galoomer.online/503187792166mkg5.pdf
    • https://sifofazawovetix.weebly.com/uploads/1/3/0/7/130776166/dijenomub.pdf
    • https://sexitikimuzulab.weebly.com/uploads/1/3/5/2/135296232/1cc13124dd.pdf
    • https://biwefixosepow.weebly.com/uploads/1/3/4/3/134334309/vatitu.pdf
    • http://dutov.org/douma_chemical_attack_report1cbqv.pdf
    • https://cdn.sqhk.co/dulemokel/aiiaGhf/merge_dragons_grimshire_secret_level_walkthrough.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/3b0d1bb5-cec0-496e-ae62-6756e03096ad/6316838685.pdf
    • https://s3.amazonaws.com/lusabifef/75847863442.pdf
    • https://s3.amazonaws.com/rewepalazamiso/98002610076.pdf
    • https://s3.amazonaws.com/libeganot/24877503347.pdf
    • https://uploads.strikinglycdn.com/files/ecedc0b1-d667-41a9-8771-af2ac1a210d8/31635036288.pdf
    • https://s3.amazonaws.com/pizivurapab/litugoletipagilujixer.pdf
    • https://uploads.strikinglycdn.com/files/a51ba267-ef97-41d6-818f-df3c23997bed/loreseva.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f562.bin
317f86c181a03a07846dd0a44bd8e4fb04c7e924f1613dd5e7d929a13368b045
pdf-font-stream PDF embedded font (sfnt) at offset 0xF562 5572 bytes
font_01_sfnt_off00010848.bin
696e0e25ae8be00938adf2b7299962a79efba97a012d12c2060665102b6ac617
pdf-font-stream PDF embedded font (sfnt) at offset 0x10848 11416 bytes