Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f521553845bce05…

MALICIOUS

PDF

115.0 KB Created: 2021-03-25 00:42:06 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9c8f36a0d6883af4eedaa760f8d1cc16 SHA-1: 3391eb3e28a95da61a7d441b92d26bbb354d01af SHA-256: 4f521553845bce0593b45c2862ef229bf31503e9430883466e2696f3471149e4
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, with a critical heuristic identifying it as a link farm. One prominent URL, 'https://ponafet.ru/wix?keyword=13.2+gr+the+genetic+code+answers', is directly embedded and likely serves as a lure for phishing or malware delivery. The ML classifier and ClamAV detection strongly indicate malicious intent, consistent with a phishing or trojan distribution campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ponafet.ru/wix?keyword=13.2+gr+the+genetic+code+answers
    • http://gakagebir.mypressonline.com/banuxozovuzaziwutag.pdf
    • https://mopotiwifatuge.weebly.com/uploads/1/3/0/8/130813373/1538013.pdf
    • http://rixadixiji.scienceontheweb.net/wubigama.pdf
    • https://wisolowiguwo.weebly.com/uploads/1/3/4/6/134630140/dapami.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://8c285b57-3156-47ce-881b-df665acc117b.filesusr.com/ugd/8d46c2_084760cef95e43c8981368747741a211.pdf?index=true
    • https://uploads.strikinglycdn.com/files/338eb9c9-36ca-48bd-ae10-9dace9be04cd/93598093910.pdf
    • https://uploads.strikinglycdn.com/files/2d3c1403-8790-4229-8cb3-bf06d3b2297a/jitoz.pdf
    • http://sabulawum.rf.gd/grade_6_maths_worksheets_with_answers.pdf
    • https://84bd2c60-91d0-47b6-9565-6ae8a6593e58.filesusr.com/ugd/963627_390ea28dbf2c4e24ad72783814ae4c7d.pdf?index=true
    • http://kojenixerog.myartsonline.com/65221026714.pdf
    • https://uploads.strikinglycdn.com/files/be494eb2-b759-4b41-b918-c189002438eb/how_to_connect_ilive_bluetooth_speaker_to_tv.pdf
    • https://uploads.strikinglycdn.com/files/db63c433-b669-4b3b-bd09-9b94a4ea6966/24234287050.pdf
    • https://uploads.strikinglycdn.com/files/7486c692-04cf-4f26-93ef-e2f461c7c432/83281853604.pdf
    • https://6cdb29d4-22ce-4aaf-9e51-562b59d50851.filesusr.com/ugd/1b20fb_37679a5639e0404f895d142f924d72c0.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d445b911-b6a6-4af1-9e55-6f381c6ff548/84133127306.pdf
    • http://bewaxupu.rf.gd/gozozor.pdf
    • https://37976aa0-f55f-47d3-847a-8d185b13ebf6.filesusr.com/ugd/1d6212_0bd7f82a3f484ba2ae6e7d568af1c6c5.pdf?index=true
    • https://4123e755-5e7e-4fb8-b167-49ba90d37259.filesusr.com/ugd/fd3290_b730f72d54fc49cfb4b2bf4453ecb507.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000181a0.bin
109086ce06b480216e40499401b4117d8e24bde8f75c1508b314a396b88ac700
pdf-font-stream PDF embedded font (sfnt) at offset 0x181A0 5544 bytes
font_01_sfnt_off0001948a.bin
c85ca4a786443a94785150a674c5635f69aa821a7beb467e4b21315cbbca22be
pdf-font-stream PDF embedded font (sfnt) at offset 0x1948A 12988 bytes