Malicious PDF — malware analysis report

Static analysis result for SHA-256 4fe9ccf732f6c5de…

MALICIOUS

PDF

75.2 KB Created: 2020-12-26 11:31:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: af800f29d1ef9d79bb6fda4a882cd137 SHA-1: 96bb8be8dbc73368921a3fcba423cef90a0f332f SHA-256: 4fe9ccf732f6c5de5a806dd87d8ab9e2abbe9d29c664d484c313e9e17f5381e5
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, suggesting a malicious intent to direct users to potentially harmful websites. The ClamAV detection and ML classifier further support its malicious nature. While no scripts were directly extracted, the presence of numerous external URIs indicates an attempt to redirect the user, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://trafffe.ru/123?utm_term=tomahawk+live+trap+coupon+code PDF link annotation
    • https://mowolonob.weebly.com/uploads/1/3/4/8/134874237/kigaxazafo-gowipokulaxuwu-lobanurovevonap.pdfIn PDF document text
    • https://lazumuron.weebly.com/uploads/1/3/4/8/134863931/wamijegilulam.pdfIn PDF document text
    • https://cdn.sqhk.co/serojimo/ggij0Fv/skins_sonic_dash_minecraft_unofficial_download.pdfIn PDF document text
    • https://kisigitoteke.weebly.com/uploads/1/3/3/9/133997396/1161501.pdfIn PDF document text
    • https://volokosebu.weebly.com/uploads/1/3/4/8/134871595/9162609.pdfIn PDF document text
    • https://cdn.sqhk.co/pepitaji/hhGCdjj/xomimeziwemuzogode.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4481676/normal_5fc522296832d.pdfIn PDF document text
    • https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/porukofosu.pdfIn PDF document text
    • https://savaxibinis.weebly.com/uploads/1/3/3/9/133997587/zuvegujogesuda.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/gateme/bmi_chart_female.pdfIn PDF document text
    • https://s3.amazonaws.com/ravuxudibure/breakdowns_art_spiegelman.pdfIn PDF document text
    • https://s3.amazonaws.com/jebupofedijakuk/mamekotese.pdfIn PDF document text
    • https://s3.amazonaws.com/wexukufedepim/showbox_pro_apk_download.pdfIn PDF document text
    • https://s3.amazonaws.com/bejideba/wgu_c429_pre_assessment.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d355.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD355 5300 bytes
SHA-256: 8832914cc9dfbcf6831a2bb675f62fc1542e82bf772b3ec4f409a78b3a30ca95
font_01_sfnt_off0000e543.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE543 10824 bytes
SHA-256: ecfc26184aa0e0dba82ab426e60a412cc38caf9308c914bbeca440831ac9dd8b
font_02_sfnt_off00010a8e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10A8E 16144 bytes
SHA-256: 18f56b7fae04e07bc119a468ad323bdda099da77b0772854d1c47cc1f39b9f3b